Lucene search

K

Build With Parameters Security Vulnerabilities

cve
cve

CVE-2024-2216

A missing permission check in an HTTP endpoint in Jenkins docker-build-step Plugin 2.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified TCP or Unix socket URL, and to reconfigure the plugin using the provided connection test parameters, affecting...

6.4AI Score

0.0004EPSS

2024-03-06 05:15 PM
40
cve
cve

CVE-2021-21628

Jenkins Build With Parameters Plugin 1.5 and earlier does not escape parameter names and descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure...

5.4CVSS

5.2AI Score

0.001EPSS

2021-03-30 12:16 PM
49
2
cve
cve

CVE-2021-21629

A cross-site request forgery (CSRF) vulnerability in Jenkins Build With Parameters Plugin 1.5 and earlier allows attackers to build a project with attacker-specified...

8.8CVSS

8.6AI Score

0.001EPSS

2021-03-30 12:16 PM
52
2