Vulnerabilities > Jenkins > Promoted Builds > 3.6
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2022-04-12 | CVE-2022-29045 | Cross-site Scripting vulnerability in Jenkins Promoted Builds Jenkins promoted builds Plugin 873.v6149db_d64130 and earlier, except 3.10.1, does not escape the name and description of Promoted Build parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | 5.4 |
2022-04-12 | CVE-2022-29049 | Cross-site Scripting vulnerability in Jenkins Promoted Builds Jenkins promoted builds Plugin 873.v6149db_d64130 and earlier, except 3.10.1, does not validate the names of promotions defined in Job DSL, allowing attackers with Job/Configure permission to create a promotion with an unsafe name. | 5.4 |
2021-04-07 | CVE-2021-21641 | Cross-Site Request Forgery (CSRF) vulnerability in Jenkins Promoted Builds A cross-site request forgery (CSRF) vulnerability in Jenkins promoted builds Plugin 3.9 and earlier allows attackers to to promote builds. | 4.3 |