Jenkins Project Jenkins Pipeline Input Step Plugin vulnerabilities
2 known vulnerabilities affecting jenkins_project/jenkins_pipeline_input_step_plugin.
Total CVEs
2
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH2
Vulnerabilities
Page 1 of 1
CVE-2022-43407HIGHCVSS 8.8≥ unspecified, ≤ 451.vf1a_a_4f4052892022-10-19
CVE-2022-43407 [HIGH] CWE-352 CVE-2022-43407: Jenkins Pipeline: Input Step Plugin 451.vf1a_a_4f405289 and earlier does not restrict or sanitize th
Jenkins Pipeline: Input Step Plugin 451.vf1a_a_4f405289 and earlier does not restrict or sanitize the optionally specified ID of the 'input' step, which is used for the URLs that process user interactions for the given 'input' step (proceed or abort) and is not correctly encoded, allowing attackers able to configure Pipelines to have Jenkins build URL
cvelistv5nvd
CVE-2022-34177HIGHCVSS 7.5≥ unspecified, ≤ 448.v37cea_9a_10a_702022-06-23
CVE-2022-34177 [HIGH] CWE-22 CVE-2022-34177: Jenkins Pipeline: Input Step Plugin 448.v37cea_9a_10a_70 and earlier archives files uploaded for `fi
Jenkins Pipeline: Input Step Plugin 448.v37cea_9a_10a_70 and earlier archives files uploaded for `file` parameters for Pipeline `input` steps on the controller as part of build metadata, using the parameter name without sanitization as a relative path inside a build-related directory, allowing attackers able to configure Pipelines to create or replace
cvelistv5nvd