Jenkins Checkmarx vulnerabilities
4 known vulnerabilities affecting jenkins/checkmarx.
Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2023-35142HIGHCVSS 8.1≤ 2023.4.32023-06-14
CVE-2023-35142 [HIGH] CWE-295 CVE-2023-35142: Jenkins Checkmarx Plugin 2022.4.3 and earlier disables SSL/TLS validation for connections to the Che
Jenkins Checkmarx Plugin 2022.4.3 and earlier disables SSL/TLS validation for connections to the Checkmarx server by default.
nvd
CVE-2022-46684MEDIUMCVSS 5.4fixed in 2022.4.32022-12-12
CVE-2022-46684 [MEDIUM] CWE-79 CVE-2022-46684: Jenkins Checkmarx Plugin 2022.3.3 and earlier does not escape values returned from the Checkmarx ser
Jenkins Checkmarx Plugin 2022.3.3 and earlier does not escape values returned from the Checkmarx service API before inserting them into HTML reports, resulting in a stored cross-site scripting (XSS) vulnerability.
nvd
CVE-2022-25200HIGHCVSS 8.8≤ 2022.1.22022-02-15
CVE-2022-25200 [HIGH] CWE-352 CVE-2022-25200: A cross-site request forgery (CSRF) vulnerability in Jenkins Checkmarx Plugin 2022.1.2 and earlier a
A cross-site request forgery (CSRF) vulnerability in Jenkins Checkmarx Plugin 2022.1.2 and earlier allows attackers to connect to an attacker-specified webserver using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
nvd
CVE-2022-25201MEDIUMCVSS 6.5≤ 2022.1.22022-02-15
CVE-2022-25201 [MEDIUM] CWE-862 CVE-2022-25201: Missing permission checks in Jenkins Checkmarx Plugin 2022.1.2 and earlier allow attackers with Over
Missing permission checks in Jenkins Checkmarx Plugin 2022.1.2 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified webserver using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
nvd