Vulnerabilities > Jenkins > Project Inheritance > 19.08.02
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-06-30 | CVE-2022-34787 | Cross-site Scripting vulnerability in Jenkins Project Inheritance Jenkins Project Inheritance Plugin 21.04.03 and earlier does not escape the reason a build is blocked in tooltips, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able to control the reason a queue item is blocked. | 5.4 |
2020-06-03 | CVE-2020-2198 | Insufficiently Protected Credentials vulnerability in Jenkins Project Inheritance Jenkins Project Inheritance Plugin 19.08.02 and earlier does not redact encrypted secrets in the 'getConfigAsXML' API URL when transmitting job config.xml data to users without Job/Configure. | 6.5 |
2020-06-03 | CVE-2020-2197 | Incorrect Default Permissions vulnerability in Jenkins Project Inheritance Jenkins Project Inheritance Plugin 19.08.02 and earlier does not require users to have Job/ExtendedRead permission to access Inheritance Project job configurations in XML format. | 4.3 |