Jenkins Build-Metrics vulnerabilities
3 known vulnerabilities affecting jenkins/build-metrics.
Total CVEs
3
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2022-34784MEDIUMCVSS 5.4v1.32022-06-30
CVE-2022-34784 [MEDIUM] CWE-79 CVE-2022-34784: Jenkins build-metrics Plugin 1.3 does not escape the build description on one of its views, resultin
Jenkins build-metrics Plugin 1.3 does not escape the build description on one of its views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Build/Update permission.
nvd
CVE-2022-34785MEDIUMCVSS 4.3≤ 1.32022-06-30
CVE-2022-34785 [MEDIUM] CWE-863 CVE-2022-34785: Jenkins build-metrics Plugin 1.3 and earlier does not perform permission checks in multiple HTTP end
Jenkins build-metrics Plugin 1.3 and earlier does not perform permission checks in multiple HTTP endpoints, allowing attackers with Overall/Read permission to obtain information about jobs otherwise inaccessible to them.
nvd
CVE-2019-10475MEDIUMCVSS 6.1PoC≤ 1.32019-10-23
CVE-2019-10475 [MEDIUM] CWE-79 CVE-2019-10475: A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to i
A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML and JavaScript into web pages provided by this plugin.
nvd