VYPR

Maven package

org.jenkins-ci.plugins/cvs

pkg:maven/org.jenkins-ci.plugins/cvs

Vulnerabilities (3)

  • CVE-2022-29037Apr 12, 2022
    affected < 2.19.1fixed 2.19.1

    Jenkins CVS Plugin 2.19 and earlier does not escape the name and description of CVS Symbolic Name parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

  • CVE-2020-2324Dec 3, 2020
    affected < 2.17fixed 2.17

    Jenkins CVS Plugin 2.16 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2020-2184May 6, 2020
    affected < 2.16fixed 2.16

    A cross-site request forgery vulnerability in Jenkins CVS Plugin 2.15 and earlier allows attackers to create and manipulate tags, and to connect to an attacker-specified URL.