Jenkins Vrealize Orchestrator Plugin
2 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Jenkins Vrealize Orchestrator Plugin. Use it to gauge the current risk picture and drill into individual advisories.
Jenkins Vrealize Orchestrator Plugin CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 0 |
| 2026-02 | 0 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 0 |
Severity
How the 2 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Medium2
Latest CVEs
The 2 most recently published vulnerabilities affecting Jenkins Vrealize Orchestrator Plugin.
- CVE-2022-34212A missing permission check in Jenkins vRealize Orchestrator Plugin 3.0 and earlier allows attackers with Overall/Read permission to send an HTTP POST request to an attacker-specified URL.5.7
- CVE-2022-34211A cross-site request forgery (CSRF) vulnerability in Jenkins vRealize Orchestrator Plugin 3.0 and earlier allows attackers to send an HTTP POST request to an attacker-specified URL.6.5
Product grouping is registry-driven, with AI assist and human review. How it works