CVE-2020-2316
- EPSS 0.25%
- Published 04.11.2020 15:15:12
- Last modified 21.11.2024 05:25:17
Jenkins Static Analysis Utilities Plugin 1.96 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
CVE-2019-10307
- EPSS 0.19%
- Published 30.04.2019 13:29:05
- Last modified 21.11.2024 04:18:51
A cross-site request forgery vulnerability in Jenkins Static Analysis Utilities Plugin 1.95 and earlier in the DefaultGraphConfigurationView#doSave form handler method allowed attackers to change the per-job default graph configuration for all users.
CVE-2019-10308
- EPSS 0.08%
- Published 30.04.2019 13:29:05
- Last modified 21.11.2024 04:18:51
A missing permission check in Jenkins Static Analysis Utilities Plugin 1.95 and earlier in the DefaultGraphConfigurationView#doSave form handler method allowed attackers with Overall/Read permission to change the per-job default graph configuration f...
CVE-2017-1000102
- EPSS 0.05%
- Published 05.10.2017 01:29:04
- Last modified 20.04.2025 01:37:25
The Details view of some Static Analysis Utilities based plugins, was vulnerable to a persisted cross-site scripting vulnerability: Malicious users able to influence the input to these plugins, for example the console output which is parsed to extrac...