Jenkins Project Jenkins Promoted Builds Plugin vulnerabilities
3 known vulnerabilities affecting jenkins_project/jenkins_promoted_builds_plugin.
Total CVEs
3
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2022-29049MEDIUMCVSS 5.4≥ unspecified, ≤ 873.v6149db_d641302022-04-12
CVE-2022-29049 [MEDIUM] CWE-79 CVE-2022-29049: Jenkins promoted builds Plugin 873.v6149db_d64130 and earlier, except 3.10.1, does not validate the
Jenkins promoted builds Plugin 873.v6149db_d64130 and earlier, except 3.10.1, does not validate the names of promotions defined in Job DSL, allowing attackers with Job/Configure permission to create a promotion with an unsafe name.
cvelistv5nvd
CVE-2022-29045MEDIUMCVSS 5.4≥ unspecified, ≤ 873.v6149db_d641302022-04-12
CVE-2022-29045 [MEDIUM] CWE-79 CVE-2022-29045: Jenkins promoted builds Plugin 873.v6149db_d64130 and earlier, except 3.10.1, does not escape the na
Jenkins promoted builds Plugin 873.v6149db_d64130 and earlier, except 3.10.1, does not escape the name and description of Promoted Build parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
cvelistv5nvd
CVE-2021-21641MEDIUMCVSS 4.3≥ unspecified, ≤ 3.92021-04-07
CVE-2021-21641 [MEDIUM] CWE-352 CVE-2021-21641: A cross-site request forgery (CSRF) vulnerability in Jenkins promoted builds Plugin 3.9 and earlier
A cross-site request forgery (CSRF) vulnerability in Jenkins promoted builds Plugin 3.9 and earlier allows attackers to to promote builds.
cvelistv5nvd