Jenkins Project Jenkins Requests-Plugin Plugin vulnerabilities

4 known vulnerabilities affecting jenkins_project/jenkins_requests-plugin_plugin.

Total CVEs
4
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2022-34782MEDIUMCVSS 4.3≥ unspecified, ≤ 2.2.162022-06-30
CVE-2022-34782 [MEDIUM] CWE-863 CVE-2022-34782: An incorrect permission check in Jenkins requests-plugin Plugin 2.2.16 and earlier allows attackers An incorrect permission check in Jenkins requests-plugin Plugin 2.2.16 and earlier allows attackers with Overall/Read permission to view the list of pending requests.
cvelistv5nvd
CVE-2021-21676MEDIUMCVSS 4.3≥ unspecified, ≤ 2.2.72021-06-30
CVE-2021-21676 [MEDIUM] CWE-862 CVE-2021-21676: Jenkins requests-plugin Plugin 2.2.7 and earlier does not perform a permission check in an HTTP endp Jenkins requests-plugin Plugin 2.2.7 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to send test emails to an attacker-specified email address.
cvelistv5nvd
CVE-2021-21675MEDIUMCVSS 6.5≥ unspecified, ≤ 2.2.122021-06-30
CVE-2021-21675 [MEDIUM] CWE-352 CVE-2021-21675: A cross-site request forgery (CSRF) vulnerability in Jenkins requests-plugin Plugin 2.2.12 and earli A cross-site request forgery (CSRF) vulnerability in Jenkins requests-plugin Plugin 2.2.12 and earlier allows attackers to create requests and/or have administrators apply pending requests.
cvelistv5nvd
CVE-2021-21674MEDIUMCVSS 4.3≥ unspecified, ≤ 2.2.62021-06-30
CVE-2021-21674 [MEDIUM] CVE-2021-21674: A missing permission check in Jenkins requests-plugin Plugin 2.2.6 and earlier allows attackers with A missing permission check in Jenkins requests-plugin Plugin 2.2.6 and earlier allows attackers with Overall/Read permission to view the list of pending requests.
cvelistv5nvd