Vulnerabilities > Jenkins > Mashup Portlets

DATE CVE VULNERABILITY TITLE RISK
2023-04-02 CVE-2023-28679 Cross-site Scripting vulnerability in Jenkins Mashup Portlets
Jenkins Mashup Portlets Plugin 1.1.2 and earlier provides the "Generic JS Portlet" feature that lets a user populate a portlet using a custom JavaScript expression, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by authenticated attackers with Overall/Read permission.
network
low complexity
jenkins CWE-79
5.4
2019-07-11 CVE-2019-10347 Insufficiently Protected Credentials vulnerability in Jenkins Mashup Portlets
Jenkins Mashup Portlets Plugin stored credentials unencrypted on the Jenkins master where they can be viewed by users with access to the master file system.
network
low complexity
jenkins CWE-522
8.8