Jenkins Project Jenkins Proxmox Plugin vulnerabilities
2 known vulnerabilities affecting jenkins_project/jenkins_proxmox_plugin.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2022-28142P3HIGHCVSS 7.5≥ unspecified, ≤ 0.7.02022-03-29
CVE-2022-28142 [HIGH] CWE-295 CVE-2022-28142: Jenkins Proxmox Plugin 0.6.0 and earlier disables SSL/TLS certificate validation globally for the Je
Jenkins Proxmox Plugin 0.6.0 and earlier disables SSL/TLS certificate validation globally for the Jenkins controller JVM when configured to ignore SSL/TLS issues.
nvd
CVE-2022-28141P4MEDIUMCVSS 6.5≥ unspecified, ≤ 0.5.02022-03-29
CVE-2022-28141 [MEDIUM] CWE-522 CVE-2022-28141: Jenkins Proxmox Plugin 0.5.0 and earlier stores the Proxmox Datacenter password unencrypted in the g
Jenkins Proxmox Plugin 0.5.0 and earlier stores the Proxmox Datacenter password unencrypted in the global config.xml file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.
nvd