2022 CVE Vulnerabilities

27,527 CVEs published in 2022.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2022-34812MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier allows ...
CVE-2022-34811MEDIUM4.3A missing permission check in Jenkins XPath Configuration Viewer Plugin 1.1.1 and earlier allows attackers with Overall/...
CVE-2022-34810MEDIUM6.5A missing check in Jenkins RQM Plugin 2.8 and earlier allows attackers with Overall/Read permission to enumerate credent...
CVE-2022-34809MEDIUM6.5Jenkins RQM Plugin 2.8 and earlier stores a password unencrypted in its global configuration file on the Jenkins control...
CVE-2022-34808MEDIUM4.3Jenkins Cisco Spark Plugin 1.1.1 and earlier stores bearer tokens unencrypted in its global configuration file on the Je...
CVE-2022-34807MEDIUM6.5Jenkins Elasticsearch Query Plugin 1.2 and earlier stores a password unencrypted in its global configuration file on the...
CVE-2022-34806MEDIUM6.5Jenkins Jigomerge Plugin 0.9 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller ...
CVE-2022-34805MEDIUM6.5Jenkins Skype notifier Plugin 1.1.0 and earlier stores a password unencrypted in its global configuration file on the Je...
CVE-2022-34804MEDIUM4.3Jenkins OpsGenie Plugin 1.9 and earlier transmits API keys in plain text as part of the global Jenkins configuration for...
CVE-2022-34803MEDIUM4.3Jenkins OpsGenie Plugin 1.9 and earlier stores API keys unencrypted in its global configuration file and in job config.x...
CVE-2022-34802MEDIUM4.3Jenkins RocketChat Notifier Plugin 1.5.2 and earlier stores the login password and webhook token unencrypted in its glob...
CVE-2022-34801MEDIUM4.3Jenkins Build Notifications Plugin 1.5.0 and earlier transmits tokens in plain text as part of the global Jenkins config...
CVE-2022-34800MEDIUM4.3Jenkins Build Notifications Plugin 1.5.0 and earlier stores tokens unencrypted in its global configuration files on the ...
CVE-2022-34799MEDIUM4.3Jenkins Deployment Dashboard Plugin 1.0.10 and earlier stores a password unencrypted in its global configuration file on...
CVE-2022-34798MEDIUM4.3Jenkins Deployment Dashboard Plugin 1.0.10 and earlier does not perform a permission check in several HTTP endpoints, al...
CVE-2022-34797MEDIUM4.3A cross-site request forgery (CSRF) vulnerability in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attac...
CVE-2022-34796MEDIUM4.3A missing permission check in Jenkins Deployment Dashboard Plugin 1.0.10 and earlier allows attackers with Overall/Read ...
CVE-2022-34795MEDIUM5.4Jenkins Deployment Dashboard Plugin 1.0.10 and earlier does not escape environment names on its Deployment Dashboard vie...
CVE-2022-34794MEDIUM6.5Missing permission checks in Jenkins Recipe Plugin 1.2 and earlier allow attackers with Overall/Read permission to send ...
CVE-2022-34791MEDIUM5.4Jenkins Validating Email Parameter Plugin 1.10 and earlier does not escape the name and description of its parameter typ...
CVE-2022-34790MEDIUM5.4Jenkins eXtreme Feedback Panel Plugin 2.0.1 and earlier does not escape the job names used in tooltips, resulting in a s...
CVE-2022-34789MEDIUM6.5A cross-site request forgery (CSRF) vulnerability in Jenkins Matrix Reloaded Plugin 1.1.3 and earlier allows attackers t...
CVE-2022-34788MEDIUM5.4Jenkins Matrix Reloaded Plugin 1.1.3 and earlier does not escape the agent name in tooltips, resulting in a stored cross...
CVE-2022-34787MEDIUM5.4Jenkins Project Inheritance Plugin 21.04.03 and earlier does not escape the reason a build is blocked in tooltips, resul...
CVE-2022-34786MEDIUM5.4Jenkins Rich Text Publisher Plugin 1.4 and earlier does not escape the HTML message set by its post-build step, resultin...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now