VYPR

extreme-feedback Plugin

by Jenkins Project

CVEs (2)

  • CVE-2022-34790Jun 30, 2022
    risk 0.01cvss epss 0.08

    Jenkins eXtreme Feedback Panel Plugin 2.0.1 and earlier does not escape the job names used in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

  • CVE-2022-41242Sep 21, 2022
    risk 0.00cvss epss 0.00

    A missing permission check in Jenkins extreme-feedback Plugin 1.7 and earlier allows attackers with Overall/Read permission to discover information about job names attached to lamps, discover MAC and IP addresses of existing lamps, and rename lamps.