Jenkins Project Inheritance Plugin vulnerabilities

6 known vulnerabilities affecting jenkins_project/jenkins_project_inheritance_plugin.

Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM6

Vulnerabilities

Page 1 of 1
CVE-2022-34787MEDIUMCVSS 5.4≥ unspecified, ≤ 21.04.032022-06-30
CVE-2022-34787 [MEDIUM] CWE-79 CVE-2022-34787: Jenkins Project Inheritance Plugin 21.04.03 and earlier does not escape the reason a build is blocke Jenkins Project Inheritance Plugin 21.04.03 and earlier does not escape the reason a build is blocked in tooltips, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able to control the reason a queue item is blocked.
cvelistv5nvd
CVE-2020-2198MEDIUMCVSS 6.5≥ unspecified, ≤ 19.08.022020-06-03
CVE-2020-2198 [MEDIUM] CWE-522 CVE-2020-2198: Jenkins Project Inheritance Plugin 19.08.02 and earlier does not redact encrypted secrets in the 'ge Jenkins Project Inheritance Plugin 19.08.02 and earlier does not redact encrypted secrets in the 'getConfigAsXML' API URL when transmitting job config.xml data to users without Job/Configure.
cvelistv5nvd
CVE-2020-2197MEDIUMCVSS 4.3≥ unspecified, ≤ 19.08.022020-06-03
CVE-2020-2197 [MEDIUM] CWE-276 CVE-2020-2197: Jenkins Project Inheritance Plugin 19.08.02 and earlier does not require users to have Job/ExtendedR Jenkins Project Inheritance Plugin 19.08.02 and earlier does not require users to have Job/ExtendedRead permission to access Inheritance Project job configurations in XML format.
cvelistv5nvd
CVE-2019-10409MEDIUMCVSS 4.3v2.0.0 and earlier2019-09-25
CVE-2019-10409 [MEDIUM] CWE-862 CVE-2019-10409: A missing permission check in Jenkins Project Inheritance Plugin 2.0.0 and earlier allowed attackers A missing permission check in Jenkins Project Inheritance Plugin 2.0.0 and earlier allowed attackers with Overall/Read permission to trigger project generation from templates.
cvelistv5nvd
CVE-2019-10408MEDIUMCVSS 4.3v2.0.0 and earlier2019-09-25
CVE-2019-10408 [MEDIUM] CWE-352 CVE-2019-10408: A cross-site request forgery vulnerability in Jenkins Project Inheritance Plugin 2.0.0 and earlier a A cross-site request forgery vulnerability in Jenkins Project Inheritance Plugin 2.0.0 and earlier allowed attackers to trigger project generation from templates.
cvelistv5nvd
CVE-2019-10407MEDIUMCVSS 6.5v2.0.0 and earlier2019-09-25
CVE-2019-10407 [MEDIUM] CWE-200 CVE-2019-10407: Jenkins Project Inheritance Plugin 2.0.0 and earlier displayed a list of environment variables passe Jenkins Project Inheritance Plugin 2.0.0 and earlier displayed a list of environment variables passed to a build without masking sensitive variables contributed by the Mask Passwords Plugin.
cvelistv5nvd