VYPR

Publish Over FTP

by Jenkins Project

Source repositories

CVEs (2)

  • CVE-2022-29050HigApr 12, 2022
    risk 0.50cvss 8.8epss 0.01

    A cross-site request forgery (CSRF) vulnerability in Jenkins Publish Over FTP Plugin 1.16 and earlier allows attackers to connect to an FTP server using attacker-specified credentials.

  • CVE-2022-29051MedApr 12, 2022
    risk 0.21cvss 4.3epss 0.01

    Missing permission checks in Jenkins Publish Over FTP Plugin 1.16 and earlier allow attackers with Overall/Read permission to connect to an FTP server using attacker-specified credentials.