GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
4,454
Erlang
33
GitHub Actions
22
Go
2,153
Maven
5,000+
npm
3,818
NuGet
693
pip
3,492
Pub
12
RubyGems
902
Rust
903
Swift
38
Unreviewed advisories
All unreviewed
5,000+
317 advisories
Filter by severity
Jenkins Openstack Heat Plugin does not perform permission checks in methods implementing form validation
Moderate
CVE-2022-36913
was published
for
org.jenkins-ci.plugins:openstack-heat
(Maven)
Jul 28, 2022
Jenkins Deployer Framework Plugin allows attackers with Item/Read permission to read deployment logs
Moderate
CVE-2022-36891
was published
for
org.jenkins-ci.plugins:deployer-framework
(Maven)
Jul 28, 2022
Jenkins rhnpush-plugin does not perform a permission check in a method implementing form validation
Moderate
CVE-2022-36892
was published
for
org.jenkins-ci.plugins:rhnpush-plugin
(Maven)
Jul 28, 2022
Jenkins Compuware Source Code Download is missing authorization
Moderate
CVE-2022-36896
was published
for
com.compuware.jenkins:compuware-scm-downloader
(Maven)
Jul 28, 2022
Jenkins rpmsign-plugin does not perform a permission check in a method implementing form validation
Moderate
CVE-2022-36893
was published
for
org.jenkins-ci.plugins:rpmsign-plugin
(Maven)
Jul 28, 2022
Jenkins Compuware Xpediter Code Coverage Plugin Missing Authorization
Moderate
CVE-2022-36897
was published
for
com.compuware.jenkins:compuware-xpediter-code-coverage
(Maven)
Jul 28, 2022
Jenkins Compuware Topaz Utilities Plugin is missing authorization
Moderate
CVE-2022-36895
was published
for
com.compuware.jenkins:compuware-topaz-utilities
(Maven)
Jul 28, 2022
Missing permission check in Jenkins OpenShift Deployer Plugin
Moderate
CVE-2022-36909
was published
for
org.jenkins-ci.plugins:openshift-deployer
(Maven)
Jul 28, 2022
Missing permission checks in Jenkins openstack-heat Plugin
Moderate
CVE-2022-36912
was published
for
org.jenkins-ci.plugins:openstack-heat
(Maven)
Jul 28, 2022
Missing permission check in Coverity Plugin allows capturing credentials
High
CVE-2022-36921
was published
for
org.jenkins-ci.plugins:coverity
(Maven)
Jul 28, 2022
Missing permission check in Jenkins OpenShift Deployer Plugin
Moderate
CVE-2022-36907
was published
for
org.jenkins-ci.plugins:openshift-deployer
(Maven)
Jul 28, 2022
Jenkins XPath Configuration Viewer Plugin Missing Authorization vulnerability
Moderate
CVE-2022-34813
was published
for
org.jenkins-ci.plugins:xpath-config-viewer
(Maven)
Jul 1, 2022
Jenkins Failed Job Deactivator Plugin Missing Authorization vulnerability
Moderate
CVE-2022-34818
was published
for
de.einsundeins.jenkins.plugins.failedjobdeactivator:failedJobDeactivator
(Maven)
Jul 1, 2022
Jenkins RQM Plugin allows enumerating credentials IDs due to missing permission check
Moderate
CVE-2022-34810
was published
for
net.praqma:rqm-plugin
(Maven)
Jul 1, 2022
Missing Authorization in Jenkins XPath Configuration Viewer Plugin
Moderate
CVE-2022-34811
was published
for
org.jenkins-ci.plugins:xpath-config-viewer
(Maven)
Jul 1, 2022
Jenkins build-metrics Plugin Missing Authorization vulnerability
Moderate
CVE-2022-34785
was published
for
org.jenkins-ci.plugins:build-metrics
(Maven)
Jul 1, 2022
Jenkins Deployment Dashboard Plugin has Insufficiently Protected Credentials
Moderate
CVE-2022-34796
was published
for
org.jenkins-ci.plugins:ec2-deployment-dashboard
(Maven)
Jul 1, 2022
Missing permission checks in Jenkins XebiaLabs XL Release Plugin allow capturing credentials
Moderate
CVE-2022-34781
was published
for
com.xebialabs.ci:xlrelease-plugin
(Maven)
Jul 1, 2022
Missing Authorization in Jenkins Deployment Dashboard Plugin
Moderate
CVE-2022-34798
was published
for
org.jenkins-ci.plugins:ec2-deployment-dashboard
(Maven)
Jul 1, 2022
Missing permission checks in Jenkins XebiaLabs XL Release Plugin allow enumerating credentials IDs
Moderate
CVE-2022-34779
was published
for
com.xebialabs.ci:xlrelease-plugin
(Maven)
Jul 1, 2022
Missing Authorization in Jenkins Recipe Plugin
High
CVE-2022-34794
was published
for
org.jenkins-ci.plugins:recipe
(Maven)
Jul 1, 2022
Jenkins Beaker builder Plugin Missing Authorization vulnerability
Moderate
CVE-2022-34208
was published
for
org.jenkins-ci.plugins:beaker-builder
(Maven)
Jun 24, 2022
Missing permission check in Jenkins vRealize Orchestrator Plugin
Moderate
CVE-2022-34212
was published
for
org.jenkins-ci.plugins:vmware-vrealize-orchestrator
(Maven)
Jun 24, 2022
Missing permission check in Jenkins ThreadFix Plugin
Moderate
CVE-2022-34210
was published
for
org.jenkins-ci.plugins:threadfix
(Maven)
Jun 24, 2022
Jenkins EasyQA Plugin Missing Authorization vulnerability
Moderate
CVE-2022-34204
was published
for
com.geteasyqa:easyqa
(Maven)
Jun 24, 2022
ProTip!
Advisories are also available from the
GraphQL API