io.jenkins.plugins:warnings-ng
Maven7 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting io.jenkins.plugins:warnings-ngpage 1 of 1
- CVE-2019-1003008HIGHCVSS 8.8EG 8.82019-02-06
vulnerable: 1.0.0 ... 2.1.1 (15 versions)
A cross-site request forgery vulnerability exists in Jenkins Warnings Next Generation Plugin 2.1.1 and earlier in src/main/java/io/jenkins/plugins/analysis/warnings/groovy/GroovyParser.java that allows attackers to execute arbitrary code v…
- CVE-2019-1003023MEDIUMCVSS 6.1EG 6.1✓ Fixed in 2.0.02019-02-06
vulnerable: 1.0.0 ... 1.0.1 (12 versions)
A cross-site scripting vulnerability exists in Jenkins Warnings Next Generation Plugin 1.0.1 and earlier in src/main/java/io/jenkins/plugins/analysis/core/model/DetailsTableModel.java, src/main/java/io/jenkins/plugins/analysis/core/model/S…
- CVE-2019-10325MEDIUMCVSS 5.4EG 5.4✓ Fixed in 5.1.02019-05-31
vulnerable: 1.0.0 ... 5.0.0 (23 versions)
A cross-site scripting vulnerability in Jenkins Warnings NG Plugin 5.0.0 and earlier allowed attacker with Job/Configure permission to inject arbitrary JavaScript in build overview pages.
- CVE-2019-10326MEDIUMCVSS 4.3EG 4.3✓ Fixed in 5.1.02019-05-31
vulnerable: 1.0.0 ... 5.0.0 (23 versions)
A cross-site request forgery vulnerability in Jenkins Warnings NG Plugin 5.0.0 and earlier allowed attackers to reset warning counts for future builds.
- CVE-2021-21626MEDIUMCVSS 4.3EG 4.3✓ Fixed in 8.5.02021-03-18
vulnerable: 1.0.0 ... 8.4.4 (60 versions)
Jenkins Warnings Next Generation Plugin 8.4.4 and earlier does not perform a permission check in methods implementing form validation, allowing attackers with Item/Read permission but without Item/Workspace or Item/Configure permission to …
- CVE-2022-23107HIGHCVSS 8.1EG 8.1✓ Fixed in 9.0.22022-01-12
vulnerable: 1.0.0 ... 9.0.1 (75 versions)
Jenkins Warnings Next Generation Plugin 9.10.2 and earlier does not restrict the name of a file when configuring custom ID, allowing attackers with Item/Configure permission to write and read specific files with a hard-coded suffix on the …
- CVE-2023-46651MEDIUMCVSS 6.5EG 6.5✓ Fixed in 10.4.12023-10-25
vulnerable: 1.0.0 ... 9.9.0 (118 versions)
Jenkins Warnings Plugin 10.5.0 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to. This fix has been backpor…
Check whether io.jenkins.plugins:warnings-ng is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for io.jenkins.plugins:warnings-ng CVEs against the assets you own.
Start Free Scan →