Release
Jenkins · 2 CVEs
CVE-2020-2292
MEDIUM
Jenkins Release Plugin 2.10.2 and earlier does not escape the release version in badge tooltip, resulting in a stored c…
Oct 8, 2020
CVE-2018-1000013
HIGH
Jenkins Release Plugin 2.9 and earlier did not require form submissions to be submitted via POST, resulting in a CSRF v…
Jan 23, 2018
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2020-2292 | Jenkins Release Plugin 2.10.2 and earlier does not escape the release version in badge tooltip, resulting in a stored cross-site scripting (XSS) vulnerability… | MEDIUM | 0.73% | Oct 8, 2020 |
| CVE-2018-1000013 | Jenkins Release Plugin 2.9 and earlier did not require form submissions to be submitted via POST, resulting in a CSRF vulnerability allowing attackers to trigg… | HIGH | 1.02% | Jan 23, 2018 |
Showing 1 to 2 of 2 CVEs