VYPR

Folder Based Authorization Strategy

by Jenkins Project

CVEs (2)

  • CVE-2025-24401MedJan 22, 2025
    risk 0.44cvss 6.8epss 0.00

    Jenkins Folder-based Authorization Strategy Plugin 217.vd5b_18537403e and earlier does not verify that permissions configured to be granted are enabled, potentially allowing users formerly granted (typically optional permissions, like Overall/Manage) to access functionality…

  • CVE-2022-27200MedMar 15, 2022
    risk 0.24cvss 4.8epss 0.01

    Jenkins Folder-based Authorization Strategy Plugin 1.3 and earlier does not escape the names of roles shown on the configuration form, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Overall/Administer permission.