VYPR

Project Inheritance Plugin

by Jenkins Project

CVEs (6)

  • CVE-2022-34787Jun 30, 2022
    risk 0.01cvss epss 0.09

    Jenkins Project Inheritance Plugin 21.04.03 and earlier does not escape the reason a build is blocked in tooltips, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able to control the reason a queue item is blocked.

  • CVE-2020-2197Jun 3, 2020
    risk 0.00cvss epss 0.00

    Jenkins Project Inheritance Plugin 19.08.02 and earlier does not require users to have Job/ExtendedRead permission to access Inheritance Project job configurations in XML format.

  • CVE-2020-2198Jun 3, 2020
    risk 0.00cvss epss 0.00

    Jenkins Project Inheritance Plugin 19.08.02 and earlier does not redact encrypted secrets in the 'getConfigAsXML' API URL when transmitting job config.xml data to users without Job/Configure.

  • CVE-2019-10407Sep 25, 2019
    risk 0.00cvss epss 0.00

    Jenkins Project Inheritance Plugin 2.0.0 and earlier displayed a list of environment variables passed to a build without masking sensitive variables contributed by the Mask Passwords Plugin.

  • CVE-2019-10408Sep 25, 2019
    risk 0.00cvss epss 0.01

    A cross-site request forgery vulnerability in Jenkins Project Inheritance Plugin 2.0.0 and earlier allowed attackers to trigger project generation from templates.

  • CVE-2019-10409Sep 25, 2019
    risk 0.00cvss epss 0.00

    A missing permission check in Jenkins Project Inheritance Plugin 2.0.0 and earlier allowed attackers with Overall/Read permission to trigger project generation from templates.