org.jenkins-ci.plugins:promoted-builds-simple
Maven2 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.jenkins-ci.plugins:promoted-builds-simplepage 1 of 1
- CVE-2022-25202MEDIUMCVSS 4.8EG 6.82022-02-15
vulnerable: 1.7, 1.8, 1.9
Jenkins Promoted Builds (Simple) Plugin 1.9 and earlier does not escape the name of custom promotion levels, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Overall/Administer permission.
- CVE-2022-30965MEDIUMCVSS 5.4EG 8.02022-05-17
vulnerable: 1.7, 1.8, 1.9
Jenkins Promoted Builds (Simple) Plugin 1.9 and earlier does not escape the name and description of Promotion Level parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by at…
Check whether org.jenkins-ci.plugins:promoted-builds-simple is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.jenkins-ci.plugins:promoted-builds-simple CVEs against the assets you own.
Start Free Scan →