Lucene Search Jenkins Lucene Search

Do you want an email whenever new security vulnerabilities are reported in Jenkins Lucene Search?

By the Year

In 2024 there have been 0 vulnerabilities in Jenkins Lucene Search . Last year Lucene Search had 1 security vulnerability published. Right now, Lucene Search is on track to have less security vulnerabilities in 2024 than it did last year.

Year Vulnerabilities Average Score
2024 0 0.00
2023 1 4.30
2022 2 5.75
2021 0 0.00
2020 0 0.00
2019 0 0.00
2018 0 0.00

It may take a day or so for new Lucene Search vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Jenkins Lucene Search Security Vulnerabilities

Jenkins Lucene-Search Plugin 387.v938a_ecb_f7fe9 and earlier does not require POST requests for an HTTP endpoint

CVE-2023-30529 4.3 - Medium - April 12, 2023

Jenkins Lucene-Search Plugin 387.v938a_ecb_f7fe9 and earlier does not require POST requests for an HTTP endpoint, allowing attackers to reindex the database.

Session Riding

Jenkins Lucene-Search Plugin 370.v62a5f618cd3a and earlier does not perform a permission check in several HTTP endpoints

CVE-2022-36910 5.4 - Medium - July 27, 2022

Jenkins Lucene-Search Plugin 370.v62a5f618cd3a and earlier does not perform a permission check in several HTTP endpoints, allowing attackers with Overall/Read permission to reindex the database and to obtain information about jobs otherwise inaccessible to them.

AuthZ

Jenkins Lucene-Search Plugin 370.v62a5f618cd3a and earlier does not escape the search query parameter displayed on the 'search' result page

CVE-2022-36922 6.1 - Medium - July 27, 2022

Jenkins Lucene-Search Plugin 370.v62a5f618cd3a and earlier does not escape the search query parameter displayed on the 'search' result page, resulting in a reflected cross-site scripting (XSS) vulnerability.

XSS

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Jenkins Lucene Search or by Jenkins? Click the Watch button to subscribe.

Jenkins
Vendor

subscribe