Vulnerabilities > Jenkins > Project Inheritance > Medium

DATE CVE VULNERABILITY TITLE RISK
2022-06-30 CVE-2022-34787 Cross-site Scripting vulnerability in Jenkins Project Inheritance
Jenkins Project Inheritance Plugin 21.04.03 and earlier does not escape the reason a build is blocked in tooltips, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able to control the reason a queue item is blocked.
network
low complexity
jenkins CWE-79
5.4
2020-06-03 CVE-2020-2198 Insufficiently Protected Credentials vulnerability in Jenkins Project Inheritance
Jenkins Project Inheritance Plugin 19.08.02 and earlier does not redact encrypted secrets in the 'getConfigAsXML' API URL when transmitting job config.xml data to users without Job/Configure.
network
low complexity
jenkins CWE-522
6.5
2020-06-03 CVE-2020-2197 Incorrect Default Permissions vulnerability in Jenkins Project Inheritance
Jenkins Project Inheritance Plugin 19.08.02 and earlier does not require users to have Job/ExtendedRead permission to access Inheritance Project job configurations in XML format.
network
low complexity
jenkins CWE-276
4.3
2019-09-25 CVE-2019-10409 Missing Authorization vulnerability in Jenkins Project Inheritance
A missing permission check in Jenkins Project Inheritance Plugin 2.0.0 and earlier allowed attackers with Overall/Read permission to trigger project generation from templates.
network
low complexity
jenkins CWE-862
4.3
2019-09-25 CVE-2019-10408 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Project Inheritance
A cross-site request forgery vulnerability in Jenkins Project Inheritance Plugin 2.0.0 and earlier allowed attackers to trigger project generation from templates.
network
low complexity
jenkins CWE-352
4.3
2019-09-25 CVE-2019-10407 Information Exposure vulnerability in Jenkins Project Inheritance
Jenkins Project Inheritance Plugin 2.0.0 and earlier displayed a list of environment variables passed to a build without masking sensitive variables contributed by the Mask Passwords Plugin.
network
low complexity
jenkins CWE-200
6.5