Dependency Graph Viewer
Vendor:
First CVE: Jan 26, 2018 · Active for 8 years
2
Total CVEs
More Total CVEs than 53% of tracked products
1.0
Avg CVEs / Year
Bottom 1%
4.8
Avg CVSS
Higher Avg CVSS than 8% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Dependency Graph Viewer over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 26, 2018
8 years ago
Most Recent CVE
Jul 11, 2019
2,574 days ago
CVE Severity & Scoring
Dependency Graph Viewer2 CVEs
100%
All CVEs352,785 CVEs
45%
40%
11%
Medium
Attack Vector
Local0 (0.0%)
Network2 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low2 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None1 (50.0%)
Unknown0 (0.0%)
Required1 (50.0%)
Privileges Required
Low2 (100.0%)
High0 (0.0%)
None0 (0.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-10349MEDIUM A stored cross site scripting vulnerability in Jenkins Dependency Graph Viewer Plugin 0.13 and earlier allowed attackers able to configure jobs in Jenkins to inject arbitrary HTML | Jul 11, 2019 | 5.4 | 30 | NO | YES |
CVE-2017-1000388MEDIUM Jenkins Dependency Graph Viewer plugin 0.12 and earlier did not perform permission checks for the API endpoint that modifies the dependency graph, allowing anyone with Overall/Read | Jan 26, 2018 | 4.3 | 16 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (2 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
1 CVE
50.0% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (2 CVEs).
Media Mentions
Signals from CVEs in this product scope (2 CVEs).
Top CNAs Publishing CVEs For Dependency Graph Viewer
Top CWEs
Versions
No cataloged versions.