Skip to main content

Vendor/product archive

jenkins / project_inheritance CVEs

Beta · best-effort

6 CVEs tagged to jenkins / project_inheritance0 Critical, 0 High, 6 Medium, 0 Low, 0 Unrated.

CVE-2022-34787

Published Jun 30, 2022

Jenkins Project Inheritance Plugin 21.04.03 and earlier does not escape the reason a build is blocked in tooltips, resulting in a cross-site scripting (XSS) vulnerability exploita…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2198

Published Jun 3, 2020

Jenkins Project Inheritance Plugin 19.08.02 and earlier does not redact encrypted secrets in the 'getConfigAsXML' API URL when transmitting job config.xml data to users without Jo…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2197

Published Jun 3, 2020

Jenkins Project Inheritance Plugin 19.08.02 and earlier does not require users to have Job/ExtendedRead permission to access Inheritance Project job configurations in XML format.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10409

Published Sep 25, 2019

A missing permission check in Jenkins Project Inheritance Plugin 2.0.0 and earlier allowed attackers with Overall/Read permission to trigger project generation from templates.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10408

Published Sep 25, 2019

A cross-site request forgery vulnerability in Jenkins Project Inheritance Plugin 2.0.0 and earlier allowed attackers to trigger project generation from templates.

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-10407

Published Sep 25, 2019

Jenkins Project Inheritance Plugin 2.0.0 and earlier displayed a list of environment variables passed to a build without masking sensitive variables contributed by the Mask Passwo…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1