VYPR

CVS Plugin

by Jenkins Project

Source repositories

CVEs (3)

  • CVE-2022-29037Apr 12, 2022
    risk 0.00cvss epss 0.00

    Jenkins CVS Plugin 2.19 and earlier does not escape the name and description of CVS Symbolic Name parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

  • CVE-2020-2324Dec 3, 2020
    risk 0.00cvss epss 0.00

    Jenkins CVS Plugin 2.16 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2020-2184May 6, 2020
    risk 0.00cvss epss 0.01

    A cross-site request forgery vulnerability in Jenkins CVS Plugin 2.15 and earlier allows attackers to create and manipulate tags, and to connect to an attacker-specified URL.