10 Total advisories
10 Vulnerabilities
0 Malware
Dependency scanning
Check whether org.jenkins-ci.plugins.workflow:workflow-cps-global-lib is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
HIGH 8.8
CVE-2022-25174
Improper Neutralization of Special Elements used in an OS Command in Jenkins Pipeline: Shared Groovy Libraries Plugin
HIGH 8.8
CVE-2022-25182
Jenkins Pipeline: Deprecated Groovy Libraries Plugin Protection Mechanism Failure
MEDIUM 4.3
CVE-2019-10357
Missing Authorization in Jenkins Pipeline: Shared Groovy Libraries Plugin
HIGH 8.8
CVE-2022-25181
Jenkins Pipeline: Deprecated Groovy Libraries Plugin Protection Mechanism Failure
HIGH 8.8
CVE-2022-25183
Jenkins Pipeline: Deprecated Groovy Libraries Plugin Protection Mechanism Failure
HIGH 8.8
CVE-2022-43406
Sandbox bypass vulnerability in Jenkins Pipeline: Deprecated Groovy Libraries Plugin
HIGH 8.8
CVE-2022-43405
Sandbox bypass vulnerability in Jenkins Pipeline: Groovy Libraries Plugin and Pipeline: Deprecated Groovy Libraries Plugin
HIGH 7.3
CVE-2022-29047
Untrusted users can modify some Pipeline libraries in Jenkins Pipeline: Deprecated Groovy Libraries Plugin
MEDIUM 6.5
CVE-2022-25178
Improper Limitation of a Pathname to a Restricted Directory in Jenkins Pipeline: Shared Groovy Libraries Plugin
MEDIUM 6.5
CVE-2022-25177
Improper Link Resolution Before File Access in Jenkins Pipeline: Shared Groovy Libraries Plugin
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes