Jenkins Cvs vulnerabilities
2 known vulnerabilities affecting jenkins/cvs.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH1MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2022-29037MEDIUMCVSS 5.4≤ 2.192022-04-12
CVE-2022-29037 [MEDIUM] CWE-79 CVE-2022-29037: Jenkins CVS Plugin 2.19 and earlier does not escape the name and description of CVS Symbolic Name pa
Jenkins CVS Plugin 2.19 and earlier does not escape the name and description of CVS Symbolic Name parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
nvd
CVE-2020-2324HIGHCVSS 7.5≤ 2.162020-12-03
CVE-2020-2324 [HIGH] CWE-611 CVE-2020-2324: Jenkins CVS Plugin 2.16 and earlier does not configure its XML parser to prevent XML external entity
Jenkins CVS Plugin 2.16 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
nvd