Scm Httpclient
Jenkins · 2 CVEs
CVE-2022-41250
MEDIUM
A missing permission check in Jenkins SCM HttpClient Plugin 1.5 and earlier allows attackers with Overall/Read permissi…
Sep 21, 2022
CVE-2022-41249
HIGH
A cross-site request forgery (CSRF) vulnerability in Jenkins SCM HttpClient Plugin 1.5 and earlier allows attackers to…
Sep 21, 2022
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2022-41250 | A missing permission check in Jenkins SCM HttpClient Plugin 1.5 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified H… | MEDIUM | 0.66% | Sep 21, 2022 |
| CVE-2022-41249 | A cross-site request forgery (CSRF) vulnerability in Jenkins SCM HttpClient Plugin 1.5 and earlier allows attackers to connect to an attacker-specified HTTP se… | HIGH | 0.46% | Sep 21, 2022 |
Showing 1 to 2 of 2 CVEs