Veracode is an application security testing and software composition analysis platform with a compact vulnerability footprint centered on its namesake product. The observed weakness classes cluster around information exposure issues, including sensitive data leakage to unauthorized actors and inadvertent logging of sensitive material, reflecting the data-handling and logging practices typical of a cloud-hosted security scanning service. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Veracode over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-25721MEDIUM Veracode Scan Jenkins Plugin before 23.3.19.0, when the "Connect using proxy" option is enabled and configured with proxy credentials and when the Jenkins global system setting deb | Mar 28, 2023 | 6.5 | 22 | NO | NO |
CVE-2023-25722MEDIUM A credential-leak issue was discovered in related Veracode products before 2023-03-27. Veracode Scan Jenkins Plugin before 23.3.19.0, when configured for remote agent jobs, invokes | Mar 28, 2023 | 5.5 | 20 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Veracode.
Media articles that mention a CVE ID that affects a product developed by Veracode — matched by CVE ID, not by vendor name.