2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-34199 | MEDIUM | 6.5 | 0.6% | Jun 23, 2022 | Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Je... |
| CVE-2022-34198 | MEDIUM | 5.4 | 0.7% | Jun 23, 2022 | Jenkins Stash Branch Parameter Plugin 0.3.0 and earlier does not escape the name and description of Stash Branch paramet... |
| CVE-2022-34197 | MEDIUM | 5.4 | 0.6% | Jun 23, 2022 | Jenkins Sauce OnDemand Plugin 1.204 and earlier does not escape the name and description of Sauce Labs Browsers paramete... |
| CVE-2022-34196 | MEDIUM | 5.4 | 0.8% | Jun 23, 2022 | Jenkins REST List Parameter Plugin 1.5.2 and earlier does not escape the name and description of REST list parameters on... |
| CVE-2022-34195 | MEDIUM | 5.4 | 0.8% | Jun 23, 2022 | Jenkins Repository Connector Plugin 2.2.0 and earlier does not escape the name and description of Maven Repository Artif... |
| CVE-2022-34194 | MEDIUM | 5.4 | 0.6% | Jun 23, 2022 | Jenkins Readonly Parameter Plugin 1.0.0 and earlier does not escape the name and description of Readonly String and Read... |
| CVE-2022-34193 | MEDIUM | 5.4 | 0.6% | Jun 23, 2022 | Jenkins Package Version Plugin 1.0.1 and earlier does not escape the name of Package version parameters on views display... |
| CVE-2022-34192 | MEDIUM | 5.4 | 0.8% | Jun 23, 2022 | Jenkins ontrack Jenkins Plugin 4.0.0 and earlier does not escape the name of Ontrack: Multi Parameter choice, Ontrack: P... |
| CVE-2022-34191 | MEDIUM | 5.4 | 0.6% | Jun 23, 2022 | Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.77 and earlier does not escape the name of NetStorm Test pa... |
| CVE-2022-34190 | MEDIUM | 5.4 | 0.6% | Jun 23, 2022 | Jenkins Maven Metadata Plugin for Jenkins CI server Plugin 2.1 and earlier does not escape the name and description of L... |
| CVE-2022-34189 | MEDIUM | 5.4 | 0.6% | Jun 23, 2022 | Jenkins Image Tag Parameter Plugin 1.10 and earlier does not escape the name and description of Image Tag parameters on ... |
| CVE-2022-34188 | MEDIUM | 5.4 | 0.6% | Jun 23, 2022 | Jenkins Hidden Parameter Plugin 0.0.4 and earlier does not escape the name and description of Hidden Parameter parameter... |
| CVE-2022-34187 | MEDIUM | 5.4 | 0.7% | Jun 23, 2022 | Jenkins Filesystem List Parameter Plugin 0.0.7 and earlier does not escape the name and description of File system objec... |
| CVE-2022-34186 | MEDIUM | 5.4 | 0.8% | Jun 23, 2022 | Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier does not escape the name and description of Moded Ext... |
| CVE-2022-34185 | MEDIUM | 5.4 | 0.6% | Jun 23, 2022 | Jenkins Date Parameter Plugin 0.0.4 and earlier does not escape the name and description of Date parameters on views dis... |
| CVE-2022-34184 | MEDIUM | 5.4 | 0.8% | Jun 23, 2022 | Jenkins CRX Content Package Deployer Plugin 1.9 and earlier does not escape the name and description of CRX Content Pack... |
| CVE-2022-34183 | MEDIUM | 5.4 | 0.6% | Jun 23, 2022 | Jenkins Agent Server Parameter Plugin 1.1 and earlier does not escape the name and description of Agent Server parameter... |
| CVE-2022-34182 | MEDIUM | 6.1 | 0.9% | Jun 23, 2022 | Jenkins Nested View Plugin 1.20 through 1.25 (both inclusive) does not escape search parameters, resulting in a reflecte... |
| CVE-2022-34181 | CRITICAL | 9.1 | 1.2% | Jun 23, 2022 | Jenkins xUnit Plugin 3.0.8 and earlier implements an agent-to-controller message that creates a user-specified directory... |
| CVE-2022-34180 | HIGH | 7.5 | 1.1% | Jun 23, 2022 | Jenkins Embeddable Build Status Plugin 2.0.3 and earlier does not correctly perform the ViewStatus permission check in t... |
| CVE-2022-34179 | HIGH | 7.5 | 1.6% | Jun 23, 2022 | Jenkins Embeddable Build Status Plugin 2.0.3 and earlier allows specifying a `style` query parameter that is used to cho... |
| CVE-2022-34178 | MEDIUM | 6.1 | 0.9% | Jun 23, 2022 | Jenkins Embeddable Build Status Plugin 2.0.3 allows specifying a 'link' query parameter that build status badges will li... |
| CVE-2022-34177 | HIGH | 7.5 | 1.5% | Jun 23, 2022 | Jenkins Pipeline: Input Step Plugin 448.v37cea_9a_10a_70 and earlier archives files uploaded for `file` parameters for P... |
| CVE-2022-34176 | MEDIUM | 5.4 | 76.7% | Jun 23, 2022 | Jenkins JUnit Plugin 1119.va_a_5e9068da_d7 and earlier does not escape descriptions of test results, resulting in a stor... |
| CVE-2022-34175 | HIGH | 7.5 | 1.3% | Jun 23, 2022 | Jenkins 2.335 through 2.355 (both inclusive) allows attackers in some cases to bypass a protection mechanism, thereby di... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now