VYPR

Jenkins Image Tag Parameter Plugin

by Jenkins Project

CVEs (2)

  • CVE-2022-34189Jun 22, 2022
    risk 0.01cvss epss 0.17

    Jenkins Image Tag Parameter Plugin 1.10 and earlier does not escape the name and description of Image Tag parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

  • CVE-2023-30516Apr 12, 2023
    risk 0.00cvss epss 0.00

    Jenkins Image Tag Parameter Plugin 2.0 improperly introduces an option to opt out of SSL/TLS certificate validation when connecting to Docker registries, resulting in job configurations using Image Tag Parameters that were created before 2.0 having SSL/TLS certificate validation disabled by default.