VYPR

Pipeline: Build Step Plugin

by Jenkins Project

Source repositories

CVEs (2)

  • CVE-2026-84661MedSep 2, 2026
    risk 0.35cvss 5.4epss 0.00

    A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v4b_67ea_11b_152 and earlier causes downstream builds awaited by the `waitForBuild` step when the `propagateAbort` parameter is used to be canceled even when the build's authentication lacks Item/Cancel…

  • CVE-2026-84660MedSep 2, 2026
    risk 0.35cvss 5.4epss 0.00

    A missing permission check in Jenkins Pipeline: Build Step Plugin 599.v4b_67ea_11b_152 and earlier causes downstream builds triggered by the `build` step to be canceled even when the build's authentication lacks Item/Cancel permission on the downstream job.