org.jenkins-ci.plugins:subversion
Maven8 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.jenkins-ci.plugins:subversionpage 1 of 1
- CVE-2013-6372NONECVSS 0.0✓ Fixed in 1.542014-05-08
vulnerable: 1.24 ... 1.53 (25 versions)
The Subversion plugin before 1.54 for Jenkins stores credentials using base64 encoding, which allows local users to obtain passwords and SSH private keys by reading a subversion.credentials file.
- CVE-2017-1000085MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.92017-10-05
vulnerable: 1.24 ... 2.8 (55 versions)
Subversion Plugin connects to a user-specified Subversion repository as part of form validation (e.g. to retrieve a list of tags). This functionality improperly checked permissions, allowing any user with Item/Build permission (but not Ite…
- CVE-2018-1000111MEDIUMCVSS 5.3✓ Fixed in 2.10.32018-03-13
vulnerable: 1.24 ... 2.9 (59 versions)
An improper authorization vulnerability exists in Jenkins Subversion Plugin version 2.10.2 and earlier in SubversionStatus.java and SubversionRepositoryStatus.java that allows an attacker with network access to obtain a list of nodes and u…
- CVE-2020-2111MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.13.12020-02-12
vulnerable: 1.24 ... 2.9 (69 versions)
Jenkins Subversion Plugin 2.13.0 and earlier does not escape the error message for the Project Repository Base URL field form validation, resulting in a stored cross-site scripting vulnerability.
- CVE-2020-2304MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.13.22020-11-04
vulnerable: 1.24 ... 2.9 (70 versions)
Jenkins Subversion Plugin 2.13.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
- CVE-2021-21698HIGHCVSS 7.5EG 7.5✓ Fixed in 2.15.12021-11-04
vulnerable: 1.24 ... 2.9 (78 versions)
Jenkins Subversion Plugin 2.15.0 and earlier does not restrict the name of a file when looking up a subversion key file on the controller from an agent.
- CVE-2022-29046MEDIUMCVSS 5.4EG 5.4✓ Fixed in 2.15.42022-04-12
vulnerable: 1.24 ... 2.9 (81 versions)
Jenkins Subversion Plugin 2.15.3 and earlier does not escape the name and description of List Subversion tags (and more) parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable …
- CVE-2022-29048MEDIUMCVSS 4.3EG 4.3✓ Fixed in 2.15.42022-04-12
vulnerable: 1.24 ... 2.9 (81 versions)
A cross-site request forgery (CSRF) vulnerability in Jenkins Subversion Plugin 2.15.3 and earlier allows attackers to connect to an attacker-specified URL.
Check whether org.jenkins-ci.plugins:subversion is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.jenkins-ci.plugins:subversion CVEs against the assets you own.
Start Free Scan →