Open Source Vulnerabilities
org.kohsuke:libpam4j
Improper Input Validation in libpam4j
org.kohsuke:libpam4j
Improper Input Validation in libpam4j
io.undertow:undertow-core, io.undertow:undertow-core
Incorrect Authorization in Undertow
io.undertow:undertow-core/ io.undertow:undertow-core
Incorrect Authorization in Undertow
org.ovirt.engine.sdk:ovirt-engine-sdk-java
ovirt-engine Logs Plaintext Passwords To File
org.ovirt.engine.sdk:ovirt-engine-sdk-java
ovirt-engine Logs Plaintext Passwords To File
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Incomplete List of Disallowed Inputs in Jenkins
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Incomplete List of Disallowed Inputs in Jenkins
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Inadequate Encryption Strength in Jenkins
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Inadequate Encryption Strength in Jenkins
io.hawt:project
Path Traversal in io.hawt:project
io.hawt:project
Insecure cookie sharing in Hawtio
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Improper Neutralization of Input During Web Page Generation in Jenkins
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Improper Neutralization of Input During Web Page Generation in Jenkins
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Deserialization of Untrusted Data in Jenkins
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Deserialization of Untrusted Data in Jenkins
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Improper Neutralization of Input During Web Page Generation in Jenkins
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Improper Neutralization of Input During Web Page Generation in Jenkins
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Improper Authentication in Jenkins
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Improper Authentication in Jenkins
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Cross-Site Request Forgery in Jenkins
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Cross-Site Request Forgery in Jenkins
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins
org.jenkins-ci.main:jenkins-core, org.jenkins-ci.main:jenkins-core
Incorrect Permission Assignment for Critical Resource in Jenkins
org.jenkins-ci.main:jenkins-core/ org.jenkins-ci.main:jenkins-core
Incorrect Permission Assignment for Critical Resource in Jenkins
org.infinispan:infinispan-server-core
Infinispan Rest API Does Not Enforce Auth Constraints
org.infinispan:infinispan-server-core
Infinispan Rest API Does Not Enforce Auth Constraints
org.jenkins-ci.plugins:active-directory
Jenkins Active Directory Plugin did not verify certificate of AD server
org.jenkins-ci.plugins:active-directory
Jenkins Active Directory Plugin did not verify certificate of AD server
org.jenkins-ci.plugins:ssh-slaves
Jenkins SSH Build Agents Plugin did not verify host keys
org.jenkins-ci.plugins:ssh-slaves
Jenkins SSH Build Agents Plugin did not verify host keys
org.jenkins-ci.plugins:distfork
Missing permission checks in Jenkins Distributed Fork Plugin
org.jenkins-ci.plugins:distfork
Missing permission checks in Jenkins Distributed Fork Plugin
hammer_cli_foreman
hammer_cli_foreman Improper Certificate Validation vulnerability
hammer_cli_foreman
hammer_cli_foreman Improper Certificate Validation vulnerability
org.jenkins-ci.plugins:mailer
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins-mailer-plugin
org.jenkins-ci.plugins:mailer
Exposure of Sensitive Information to an Unauthorized Actor in Jenkins-mailer-plugin
org.jenkins-ci.plugins:email-ext
Emails were sent to addresses not associated with actual users of Jenkins by Email Extension Plugin
org.jenkins-ci.plugins:email-ext
Emails were sent to addresses not associated with actual users of Jenkins by Email Extension Plugin
katello
katello Improper Privilege Management vulnerability
katello
katello Improper Privilege Management vulnerability
cprice404:pipeline-classpath
Jenkins Pipeline Classpath Step plugin allowed Script Security sandbox bypass
cprice404:pipeline-classpath
Jenkins Pipeline Classpath Step plugin allowed Script Security sandbox bypass
org.springframework.flex:spring-flex
Deserialization of Untrusted Data in Spring-flex
org.springframework.flex:spring-flex
Deserialization of Untrusted Data in Spring-flex
com.exadel.flamingo.flex:amf-serializer
Deserialization of Untrusted Data in Flamingo amf-serializer
com.exadel.flamingo.flex:amf-serializer
Deserialization of Untrusted Data in Flamingo amf-serializer
drupal/core, drupal/core, drupal/drupal, drupal/drupal
Drupal core access bypass vulnerability
drupal/core/ drupal/core/ drupal/drupal/ drupal/drupal
Drupal core access bypass vulnerability
drupal/core, drupal/drupal
Drupal file REST resource does not properly validate
drupal/core/ drupal/drupal
Drupal file REST resource does not properly validate
drupal/core, drupal/drupal
Drupal REST API can bypass comment approval
drupal/core/ drupal/drupal
Drupal REST API can bypass comment approval
org.jbpm.jbpm5:jbpmmigration
XML External Entity Reference in jbpmmigration
org.jbpm.jbpm5:jbpmmigration
XML External Entity Reference in jbpmmigration
io.hawt:project
Cross-Site Request Forgery in hawtio
io.undertow:undertow-core, io.undertow:undertow-core, io.undertow:undertow-core
Undertow vulnerable to Request Smuggling
io.undertow:undertow-core/ io.undertow:undertow-core/ io.undertow:undertow-core
Undertow vulnerable to Request Smuggling
org.elasticsearch.plugin:x-pack
Improper Privilege Management in X-Pack
org.elasticsearch.plugin:x-pack
Improper Privilege Management in X-Pack
net.lingala.zip4j:zip4j
Improper Limitation of a Pathname to a Restricted Directory in Zip4j
net.lingala.zip4j:zip4j
Improper Limitation of a Pathname to a Restricted Directory in Zip4j
k8s.io/kubernetes
Kubernetes arbitrary file overwrite
k8s.io/minikube
Minikube RCE via DNS Rebinding
org.codehaus.plexus:plexus-archiver
Improper Limitation of a Pathname to a Restricted Directory in plexus-archiver
org.codehaus.plexus:plexus-archiver
Improper Limitation of a Pathname to a Restricted Directory in plexus-archiver
SharpZipLib
Improper Limitation of a Pathname to a Restricted Directory in SharpZipLib
SharpZipLib
Improper Limitation of a Pathname to a Restricted Directory in SharpZipLib
github.com/containers/podman
Podman Elevated Container Privileges
github.com/containers/podman
Podman Elevated Container Privileges
org.keycloak:keycloak-saml-adapter-core, org.keycloak:keycloak-services
Keycloak Authentication Error
org.keycloak:keycloak-saml-adapter-core/ org.keycloak:keycloak-services
Keycloak Authentication Error
moodle/moodle, moodle/moodle, moodle/moodle, moodle/moodle
Moodle Exposure of Sensitive Information to an Unauthorized Actor
moodle/moodle/ moodle/moodle/ moodle/moodle/ moodle/moodle
Moodle Exposure of Sensitive Information to an Unauthorized Actor
moodle/moodle, moodle/moodle, moodle/moodle
Moodle sensitive information disclosure
moodle/moodle/ moodle/moodle/ moodle/moodle
Moodle sensitive information disclosure
katello
katello SQL Injection vulnerability
neutron, neutron, neutron
Openstack Neutron vulnerable to eavesdropping on private traffic
neutron/ neutron/ neutron
Openstack Neutron vulnerable to eavesdropping on private traffic
moodle/moodle, moodle/moodle, moodle/moodle, moodle/moodle
Moodle XML import of ddwtos could lead to intentional remote code execution
moodle/moodle/ moodle/moodle/ moodle/moodle/ moodle/moodle
Moodle XML import of ddwtos could lead to intentional remote code execution
moodle/moodle, moodle/moodle, moodle/moodle
Moodle Cross-site Scripting
moodle/moodle/ moodle/moodle/ moodle/moodle
Moodle Cross-site Scripting
github.com/evanphx/json-patch, github.com/evanphx/json-patch
JSON-Patch Out-of-bounds Write vulnerability
github.com/evanphx/json-patch/ github.com/evanphx/json-patch
JSON-Patch Out-of-bounds Write vulnerability
org.keycloak:keycloak-core
Keycloak Open Redirect
