Vulnerabilities > Jenkins > Image TAG Parameter > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-04-12 | CVE-2023-30516 | Improper Certificate Validation vulnerability in Jenkins Image TAG Parameter Jenkins Image Tag Parameter Plugin 2.0 improperly introduces an option to opt out of SSL/TLS certificate validation when connecting to Docker registries, resulting in job configurations using Image Tag Parameters that were created before 2.0 having SSL/TLS certificate validation disabled by default. | 6.5 |
2022-06-23 | CVE-2022-34189 | Cross-site Scripting vulnerability in Jenkins Image TAG Parameter Jenkins Image Tag Parameter Plugin 1.10 and earlier does not escape the name and description of Image Tag parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | 5.4 |