cbcvebase.

Jenkins Project Jenkins Promoted Builds Plugin vulnerabilities

5 known vulnerabilities affecting jenkins_project/jenkins_promoted_builds_plugin.

Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM5

Vulnerabilities

Page 1 of 1
CVE-2022-29049P4MEDIUMCVSS 5.4≥ unspecified, ≤ 873.v6149db_d641302022-04-12
CVE-2022-29049 [MEDIUM] CWE-79 CVE-2022-29049: Jenkins promoted builds Plugin 873.v6149db_d64130 and earlier, except 3.10.1, does not validate the Jenkins promoted builds Plugin 873.v6149db_d64130 and earlier, except 3.10.1, does not validate the names of promotions defined in Job DSL, allowing attackers with Job/Configure permission to create a promotion with an unsafe name.
nvd
CVE-2022-29045P4MEDIUMCVSS 5.4≥ unspecified, ≤ 873.v6149db_d641302022-04-12
CVE-2022-29045 [MEDIUM] CWE-79 CVE-2022-29045: Jenkins promoted builds Plugin 873.v6149db_d64130 and earlier, except 3.10.1, does not escape the na Jenkins promoted builds Plugin 873.v6149db_d64130 and earlier, except 3.10.1, does not escape the name and description of Promoted Build parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
nvd
CVE-2022-30965P4MEDIUMCVSS 5.4≥ unspecified, ≤ 1.92022-05-17
CVE-2022-30965 [MEDIUM] CWE-79 CVE-2022-30965: Jenkins Promoted Builds (Simple) Plugin 1.9 and earlier does not escape the name and description of Jenkins Promoted Builds (Simple) Plugin 1.9 and earlier does not escape the name and description of Promotion Level parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
nvd
CVE-2022-25202P4MEDIUMCVSS 4.8≥ unspecified, ≤ 1.92022-02-15
CVE-2022-25202 [MEDIUM] CWE-79 CVE-2022-25202: Jenkins Promoted Builds (Simple) Plugin 1.9 and earlier does not escape the name of custom promotion Jenkins Promoted Builds (Simple) Plugin 1.9 and earlier does not escape the name of custom promotion levels, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Overall/Administer permission.
nvd
CVE-2021-21641P4MEDIUMCVSS 4.3≥ unspecified, ≤ 3.92021-04-07
CVE-2021-21641 [MEDIUM] CWE-352 CVE-2021-21641: A cross-site request forgery (CSRF) vulnerability in Jenkins promoted builds Plugin 3.9 and earlier A cross-site request forgery (CSRF) vulnerability in Jenkins promoted builds Plugin 3.9 and earlier allows attackers to to promote builds.
nvd
Jenkins Project Jenkins Promoted Builds Plugin vulnerabilities | cvebase