GitHub Advisory Database
Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.
GitHub reviewed advisories
Unreviewed advisories
Filter advisories
Filter advisories
GitHub reviewed advisories
All reviewed
5,000+
Composer
5,000+
Erlang
40
GitHub Actions
38
Go
2,761
Maven
5,000+
npm
4,368
NuGet
767
pip
4,137
Pub
12
RubyGems
962
Rust
1,070
Swift
45
Unreviewed advisories
All unreviewed
5,000+
160 advisories
Filter by severity
Cross-site request forgery vulnerability in Jenkins OpenID Plugin
High
CVE-2023-24446
was published
for
org.jenkins-ci.plugins:openid
(Maven)
Jan 26, 2023
CSRF vulnerability in Jenkins Orka Plugin allow capturing credentials
High
CVE-2023-24432
was published
for
io.jenkins.plugins:macstadium-orka
(Maven)
Jan 26, 2023
Cross-site request forgery vulnerability in Jenkins BearyChat Plugin
High
CVE-2023-24458
was published
for
org.jenkins-ci.plugins:bearychat
(Maven)
Jan 26, 2023
Cross-Site Request Forgery (CSRF) allowing to delete or rename tags
High
CVE-2022-41927
was published
for
org.xwiki.platform:xwiki-platform-tag-ui
(Maven)
Nov 21, 2022
CSRF protection for any URL can be bypassed in Jenkins Pipeline: Input Step Plugin
High
CVE-2022-43407
was published
for
org.jenkins-ci.plugins:pipeline-input-step
(Maven)
Oct 19, 2022
Jenkins Pipeline: Stage View Plugin allows CSRF protection bypass of any target URL in Jenkins
High
CVE-2022-43408
was published
for
org.jenkins-ci.plugins.pipeline-stage-view:pipeline-stage-view
(Maven)
Oct 19, 2022
Jenkins build-publisher plugin vulnerable to cross-site request forgery
High
CVE-2022-41232
was published
for
org.jenkins-ci.plugins:build-publisher
(Maven)
Sep 22, 2022
Apache JSPWiki CSRF due to crafted invocation on the Image plugin
High
CVE-2022-34158
was published
for
org.apache.jspwiki:jspwiki-main
(Maven)
Aug 5, 2022
Jenkins Coverity Plugin vulnerable to cross-site request forgery (CSRF)
High
CVE-2022-36920
was published
for
org.jenkins-ci.plugins:coverity
(Maven)
Jul 28, 2022
Togglz console missing cross-site request forgery (CSRF) protection
High
CVE-2020-28191
was published
for
org.togglz:togglz-console
(Maven)
Jul 15, 2022
Cross-Site Request Forgery in Jenkins Recipe Plugin
High
CVE-2022-34792
was published
for
org.jenkins-ci.plugins:recipe
(Maven)
Jul 1, 2022
Cross Site Request Forgery in Mingsoft MCMS
High
CVE-2022-29647
was published
for
net.mingsoft:ms-mcms
(Maven)
Jun 3, 2022
Jenkins SAML Plugin allows bypassing CSRF protection for any URL
High
CVE-2021-21678
was published
for
org.jenkins-ci.plugins:saml
(Maven)
May 24, 2022
Jenkins Azure AD Plugin allows bypassing CSRF protection for any URL
High
CVE-2021-21679
was published
for
org.jenkins-ci.plugins:azure-ad
(Maven)
May 24, 2022
Cross-Site Request Forgery in OWASP CSRFGuard
High
CVE-2021-28490
was published
for
org.owasp:csrfguard
(Maven)
May 24, 2022
Liferay Portal Layout Module and Liferay DXP Exposes the Cross-Site Request Forgery (CSRF) Token in URLs
High
CVE-2021-33338
was published
for
com.liferay.portal:release.dxp.bom
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins XebiaLabs XL Deploy Plugin allows capturing credentials
High
CVE-2021-21665
was published
for
com.xebialabs.deployit.ci:deployit-plugin
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins Team Foundation Server Plugin allow capturing credentials
High
CVE-2021-21638
was published
for
org.jenkins-ci.plugins:tfs
(Maven)
May 24, 2022
CSRF vulnerability and in Jenkins OWASP Dependency-Track Plugin allow capturing credentials
High
CVE-2021-21633
was published
for
org.jenkins-ci.plugins:dependency-track
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins Build With Parameters Plugin
High
CVE-2021-21629
was published
for
org.jenkins-ci.plugins:build-with-parameters
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins Libvirt Agents Plugin
High
CVE-2021-21627
was published
for
org.jenkins-ci.plugins:libvirt-slave
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins Configuration Slicing Plugin
High
CVE-2021-21617
was published
for
org.jenkins-ci.plugins:configurationslicing
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins Shelve Project Plugin
High
CVE-2020-2321
was published
for
org.jenkins-ci.plugins:shelve-project-plugin
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins warnings Plugin allows remote code execution
High
CVE-2020-2280
was published
for
org.jvnet.hudson.plugins:warnings
(Maven)
May 24, 2022
CSRF vulnerability in Jenkins Database Plugin
High
CVE-2020-2240
was published
for
org.jenkins-ci.plugins:database
(Maven)
May 24, 2022
ProTip!
Advisories are also available from the
GraphQL API