8 Total advisories
8 Vulnerabilities
0 Malware
Dependency scanning
Check whether org.jenkins-ci.plugins:jobConfigHistory is in your codebase
Corgea flags malicious and compromised dependencies with reachability analysis, so you fix the packages that actually run in your application instead of working through the whole lockfile.
Vulnerabilities
MEDIUM 4.3
CVE-2026-57287
Jenkins Job Configuration History Plugin doesn't redact encrypted values of secrets in job and agent configurations
MEDIUM 6.1
CVE-2018-1000416
Jenkins Job Config History Plugin reflected XSS vulnerability
MEDIUM 5.4
CVE-2023-41931
XSS vulnerability in Jenkins Job Configuration History Plugin
HIGH 8.8
CVE-2023-41933
Job Configuration History Plugin's path traversal allows exploiting XXE vulnerability
MEDIUM 4.3
CVE-2022-36887
Jenkins Job Configuration History Plugin does not require POST requests for several HTTP endpoints
MEDIUM 5.4
CVE-2022-38664
Cross-site Scripting in Jenkins Job Configuration History Plugin
MEDIUM 4.3
CVE-2023-41930
Path traversal in Jenkins Job Configuration History Plugin
MEDIUM 6.5
CVE-2023-41932
Path traversal allows exploiting XXE vulnerability in Jenkins Job Configuration History Plugin
Browse more Maven advisories
Learn What is SAST?
Static Application Security Testing finds vulnerabilities like this one in source code before it ships. Read the guide →
Ready to move
Start Securing
Free, no credit card | First findings in minutes