Jenkins Project Jenkins Build-Metrics Plugin vulnerabilities
3 known vulnerabilities affecting jenkins_project/jenkins_build-metrics_plugin.
Total CVEs
3
CISA KEV
0
Public exploits
1
Exploited in wild
0
Severity breakdown
MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2022-34784MEDIUMCVSS 5.4v1.32022-06-30
CVE-2022-34784 [MEDIUM] CWE-79 CVE-2022-34784: Jenkins build-metrics Plugin 1.3 does not escape the build description on one of its views, resultin
Jenkins build-metrics Plugin 1.3 does not escape the build description on one of its views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Build/Update permission.
cvelistv5nvd
CVE-2022-34785MEDIUMCVSS 4.3≥ unspecified, ≤ 1.32022-06-30
CVE-2022-34785 [MEDIUM] CWE-863 CVE-2022-34785: Jenkins build-metrics Plugin 1.3 and earlier does not perform permission checks in multiple HTTP end
Jenkins build-metrics Plugin 1.3 and earlier does not perform permission checks in multiple HTTP endpoints, allowing attackers with Overall/Read permission to obtain information about jobs otherwise inaccessible to them.
cvelistv5nvd
CVE-2019-10475MEDIUMCVSS 6.1PoCv1.3 and earlier2019-10-23
CVE-2019-10475 [MEDIUM] CWE-79 CVE-2019-10475: A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to i
A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML and JavaScript into web pages provided by this plugin.
cvelistv5nvd