Vulnerabilities > Jenkins > Generic Webhook Trigger

DATE CVE VULNERABILITY TITLE RISK
2022-10-19 CVE-2022-43412 Information Exposure Through Discrepancy vulnerability in Jenkins Generic Webhook Trigger
Jenkins Generic Webhook Trigger Plugin 1.84.1 and earlier uses a non-constant time comparison function when checking whether the provided and expected webhook token are equal, potentially allowing attackers to use statistical methods to obtain a valid webhook token.
network
low complexity
jenkins CWE-203
5.3
2022-02-15 CVE-2022-25185 Cross-site Scripting vulnerability in Jenkins Generic Webhook Trigger
Jenkins Generic Webhook Trigger Plugin 1.81 and earlier does not escape the build cause when using the webhook, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
network
low complexity
jenkins CWE-79
5.4
2021-06-18 CVE-2021-21669 Unspecified vulnerability in Jenkins Generic Webhook Trigger
Jenkins Generic Webhook Trigger Plugin 1.72 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
network
low complexity
jenkins
critical
9.8