Jenkins Project Jenkins Checkmarx Plugin vulnerabilities

4 known vulnerabilities affecting jenkins_project/jenkins_checkmarx_plugin.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2023-35142HIGHCVSS 8.1≤ 2022.4.32023-06-14
CVE-2023-35142 [HIGH] CWE-295 CVE-2023-35142: Jenkins Checkmarx Plugin 2022.4.3 and earlier disables SSL/TLS validation for connections to the Che Jenkins Checkmarx Plugin 2022.4.3 and earlier disables SSL/TLS validation for connections to the Checkmarx server by default.
cvelistv5nvd
CVE-2022-46684MEDIUMCVSS 5.4≥ unspecified, ≤ 2022.3.32022-12-12
CVE-2022-46684 [MEDIUM] CWE-79 CVE-2022-46684: Jenkins Checkmarx Plugin 2022.3.3 and earlier does not escape values returned from the Checkmarx ser Jenkins Checkmarx Plugin 2022.3.3 and earlier does not escape values returned from the Checkmarx service API before inserting them into HTML reports, resulting in a stored cross-site scripting (XSS) vulnerability.
cvelistv5nvd
CVE-2022-25200HIGHCVSS 8.8≥ unspecified, ≤ 2022.1.22022-02-15
CVE-2022-25200 [HIGH] CWE-352 CVE-2022-25200: A cross-site request forgery (CSRF) vulnerability in Jenkins Checkmarx Plugin 2022.1.2 and earlier a A cross-site request forgery (CSRF) vulnerability in Jenkins Checkmarx Plugin 2022.1.2 and earlier allows attackers to connect to an attacker-specified webserver using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
cvelistv5nvd
CVE-2022-25201MEDIUMCVSS 6.5≥ unspecified, ≤ 2022.1.22022-02-15
CVE-2022-25201 [MEDIUM] CWE-862 CVE-2022-25201: Missing permission checks in Jenkins Checkmarx Plugin 2022.1.2 and earlier allow attackers with Over Missing permission checks in Jenkins Checkmarx Plugin 2022.1.2 and earlier allow attackers with Overall/Read permission to connect to an attacker-specified webserver using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
cvelistv5nvd