VYPR

Gradle Plugin

by Jenkins Project

CVEs (2)

  • CVE-2023-39152MedJul 26, 2023
    risk 0.42cvss 6.5epss 0.01

    Always-incorrect control flow implementation in Jenkins Gradle Plugin 2.8 may result in credentials not being masked (i.e., replaced with asterisks) in the build log in some circumstances.

  • CVE-2026-92132MedSep 16, 2026
    risk 0.35cvss 5.4epss 0.00

    Jenkins Gradle Plugin 2.19.1252.v15196b_5a_6e10 and earlier requests build scan data from the build scan link detected in the build log, even when a Develocity server URL is configured in the global configuration, allowing attackers able to control the build log to capture the…