2022 CVE Vulnerabilities

27,552 CVEs published in 2022.

CVE IDSeverityCVSSDescription
CVE-2022-34199MEDIUM6.5Jenkins Convertigo Mobile Platform Plugin 1.1 and earlier stores passwords unencrypted in job config.xml files on the Je...
CVE-2022-34198MEDIUM5.4Jenkins Stash Branch Parameter Plugin 0.3.0 and earlier does not escape the name and description of Stash Branch paramet...
CVE-2022-34197MEDIUM5.4Jenkins Sauce OnDemand Plugin 1.204 and earlier does not escape the name and description of Sauce Labs Browsers paramete...
CVE-2022-34196MEDIUM5.4Jenkins REST List Parameter Plugin 1.5.2 and earlier does not escape the name and description of REST list parameters on...
CVE-2022-34195MEDIUM5.4Jenkins Repository Connector Plugin 2.2.0 and earlier does not escape the name and description of Maven Repository Artif...
CVE-2022-34194MEDIUM5.4Jenkins Readonly Parameter Plugin 1.0.0 and earlier does not escape the name and description of Readonly String and Read...
CVE-2022-34193MEDIUM5.4Jenkins Package Version Plugin 1.0.1 and earlier does not escape the name of Package version parameters on views display...
CVE-2022-34192MEDIUM5.4Jenkins ontrack Jenkins Plugin 4.0.0 and earlier does not escape the name of Ontrack: Multi Parameter choice, Ontrack: P...
CVE-2022-34191MEDIUM5.4Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.77 and earlier does not escape the name of NetStorm Test pa...
CVE-2022-34190MEDIUM5.4Jenkins Maven Metadata Plugin for Jenkins CI server Plugin 2.1 and earlier does not escape the name and description of L...
CVE-2022-34189MEDIUM5.4Jenkins Image Tag Parameter Plugin 1.10 and earlier does not escape the name and description of Image Tag parameters on ...
CVE-2022-34188MEDIUM5.4Jenkins Hidden Parameter Plugin 0.0.4 and earlier does not escape the name and description of Hidden Parameter parameter...
CVE-2022-34187MEDIUM5.4Jenkins Filesystem List Parameter Plugin 0.0.7 and earlier does not escape the name and description of File system objec...
CVE-2022-34186MEDIUM5.4Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier does not escape the name and description of Moded Ext...
CVE-2022-34185MEDIUM5.4Jenkins Date Parameter Plugin 0.0.4 and earlier does not escape the name and description of Date parameters on views dis...
CVE-2022-34184MEDIUM5.4Jenkins CRX Content Package Deployer Plugin 1.9 and earlier does not escape the name and description of CRX Content Pack...
CVE-2022-34183MEDIUM5.4Jenkins Agent Server Parameter Plugin 1.1 and earlier does not escape the name and description of Agent Server parameter...
CVE-2022-34182MEDIUM6.1Jenkins Nested View Plugin 1.20 through 1.25 (both inclusive) does not escape search parameters, resulting in a reflecte...
CVE-2022-34181CRITICAL9.1Jenkins xUnit Plugin 3.0.8 and earlier implements an agent-to-controller message that creates a user-specified directory...
CVE-2022-34180HIGH7.5Jenkins Embeddable Build Status Plugin 2.0.3 and earlier does not correctly perform the ViewStatus permission check in t...
CVE-2022-34179HIGH7.5Jenkins Embeddable Build Status Plugin 2.0.3 and earlier allows specifying a `style` query parameter that is used to cho...
CVE-2022-34178MEDIUM6.1Jenkins Embeddable Build Status Plugin 2.0.3 allows specifying a 'link' query parameter that build status badges will li...
CVE-2022-34177HIGH7.5Jenkins Pipeline: Input Step Plugin 448.v37cea_9a_10a_70 and earlier archives files uploaded for `file` parameters for P...
CVE-2022-34176MEDIUM5.4Jenkins JUnit Plugin 1119.va_a_5e9068da_d7 and earlier does not escape descriptions of test results, resulting in a stor...
CVE-2022-34175HIGH7.5Jenkins 2.335 through 2.355 (both inclusive) allows attackers in some cases to bypass a protection mechanism, thereby di...

Check if your code is affected by 2022 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now