Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown
CVE-2022-34787
Disclosure Date: June 30, 2022 (last updated February 24, 2025)
Jenkins Project Inheritance Plugin 21.04.03 and earlier does not escape the reason a build is blocked in tooltips, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able to control the reason a queue item is blocked.
0
Attacker Value
Unknown
CVE-2020-2197
Disclosure Date: June 03, 2020 (last updated February 21, 2025)
Jenkins Project Inheritance Plugin 19.08.02 and earlier does not require users to have Job/ExtendedRead permission to access Inheritance Project job configurations in XML format.
0
Attacker Value
Unknown
CVE-2020-2198
Disclosure Date: June 03, 2020 (last updated February 21, 2025)
Jenkins Project Inheritance Plugin 19.08.02 and earlier does not redact encrypted secrets in the 'getConfigAsXML' API URL when transmitting job config.xml data to users without Job/Configure.
0
Attacker Value
Unknown
CVE-2019-10409
Disclosure Date: September 25, 2019 (last updated October 26, 2023)
A missing permission check in Jenkins Project Inheritance Plugin 2.0.0 and earlier allowed attackers with Overall/Read permission to trigger project generation from templates.
0
Attacker Value
Unknown
CVE-2019-10408
Disclosure Date: September 25, 2019 (last updated October 26, 2023)
A cross-site request forgery vulnerability in Jenkins Project Inheritance Plugin 2.0.0 and earlier allowed attackers to trigger project generation from templates.
0
Attacker Value
Unknown
CVE-2019-10407
Disclosure Date: September 25, 2019 (last updated October 26, 2023)
Jenkins Project Inheritance Plugin 2.0.0 and earlier displayed a list of environment variables passed to a build without masking sensitive variables contributed by the Mask Passwords Plugin.
0