Jenkins Project Jenkins Subversion Partial Release Manager Plugin vulnerabilities
5 known vulnerabilities affecting jenkins_project/jenkins_subversion_partial_release_manager_plugin.
Total CVEs
5
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
MEDIUM5
Vulnerabilities
Page 1 of 1
CVE-2024-34148MEDIUMCVSS 4.3≤ 1.0.12024-05-02
CVE-2024-34148 [MEDIUM] CVE-2024-34148: Jenkins Subversion Partial Release Manager Plugin 1
Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier programmatically disables the fix for CVE-2016-3721 whenever a build is triggered from a release tag, by setting the Java system property 'hudson.model.ParametersAction.keepUndefinedParameters'.
cvelistv5
CVE-2024-28158MEDIUMCVSS 4.3≤ 1.0.12024-03-06
CVE-2024-28158 [MEDIUM] CWE-352 CVE-2024-28158: A cross-site request forgery (CSRF) vulnerability in Jenkins Subversion Partial Release Manager Plug
A cross-site request forgery (CSRF) vulnerability in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier allows attackers to trigger a build.
cvelistv5nvd
CVE-2024-28159MEDIUMCVSS 4.3≤ 1.0.12024-03-06
CVE-2024-28159 [MEDIUM] CWE-862 CVE-2024-28159: A missing permission check in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier al
A missing permission check in Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier allows attackers with Item/Read permission to trigger a build.
cvelistv5nvd
CVE-2020-2199MEDIUMCVSS 6.1≥ unspecified, ≤ 1.0.12020-06-03
CVE-2020-2199 [MEDIUM] CWE-79 CVE-2020-2199: Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier does not escape the error messag
Jenkins Subversion Partial Release Manager Plugin 1.0.1 and earlier does not escape the error message for the repository URL field form validation, resulting in a reflected cross-site scripting vulnerability.
cvelistv5nvd
CVE-2016-3721MEDIUMCVSS 4.3≤ 1.0.12016-05-17
CVE-2016-3721 [MEDIUM] CWE-17 CVE-2016-3721: Jenkins before 2.3 and LTS before 1.651.2 might allow remote authenticated users to inject arbitrary
Jenkins before 2.3 and LTS before 1.651.2 might allow remote authenticated users to inject arbitrary build parameters into the build environment via environment variables.
nvd