Jenkins Parameterized Trigger vulnerabilities
2 known vulnerabilities affecting jenkins/parameterized_trigger.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM2
Vulnerabilities
Page 1 of 1
CVE-2022-27195MEDIUMCVSS 5.5fixed in 2.43.12022-03-15
CVE-2022-27195 [MEDIUM] CVE-2022-27195: Jenkins Parameterized Trigger Plugin 2.43 and earlier captures environment variables passed to build
Jenkins Parameterized Trigger Plugin 2.43 and earlier captures environment variables passed to builds triggered using Jenkins Parameterized Trigger Plugin, including password parameter values, in their `build.xml` files. These values are stored unencrypted and can be viewed by users with access to the Jenkins controller file system.
nvd
CVE-2017-1000084MEDIUMCVSS 6.5v1.0v1.1+40 more2017-10-05
CVE-2017-1000084 [MEDIUM] CWE-276 CVE-2017-1000084: Parameterized Trigger Plugin fails to check Item/Build permission: The Parameterized Trigger Plugin
Parameterized Trigger Plugin fails to check Item/Build permission: The Parameterized Trigger Plugin did not check the build authentication it was running as and allowed triggering any other project in Jenkins.
nvd