org.jenkins-ci.plugins:sonar-gerrit
Maven2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.jenkins-ci.plugins:sonar-gerritpage 1 of 1
- CVE-2019-10467MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.4.52019-10-23
vulnerable: 1.0 ... 2.4.4 (15 versions)
Jenkins Sonar Gerrit Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
- CVE-2022-46688MEDIUMCVSS 6.5EG 6.5✓ Fixed in 378.vf4646d4df0872022-12-12
vulnerable: 1.0 ... 377.v8f3808963dc5 (32 versions)
A cross-site request forgery (CSRF) vulnerability in Jenkins Sonar Gerrit Plugin 377.v8f3808963dc5 and earlier allows attackers to have Jenkins connect to Gerrit servers (previously configured by Jenkins administrators) using attacker-spec…
Check whether org.jenkins-ci.plugins:sonar-gerrit is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.jenkins-ci.plugins:sonar-gerrit CVEs against the assets you own.
Start Free Scan →