org.jenkins-ci.plugins:scriptler
Maven5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.jenkins-ci.plugins:scriptlerpage 1 of 1
- CVE-2021-21667MEDIUMCVSS 5.4EG 5.4✓ Fixed in 3.32021-06-16
vulnerable: 2.0 ... 3.2 (16 versions)
Jenkins Scriptler Plugin 3.2 and earlier does not escape parameter names shown in job configuration forms, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Scriptler/Configure permission.
- CVE-2021-21668MEDIUMCVSS 5.4EG 5.4✓ Fixed in 3.22021-06-16
vulnerable: 2.0 ... 3.1 (15 versions)
Jenkins Scriptler Plugin 3.1 and earlier does not escape script content, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Scriptler/Configure permission.
- CVE-2021-21700MEDIUMCVSS 5.4EG 5.4✓ Fixed in 3.42021-11-12
vulnerable: 2.0 ... 3.3 (17 versions)
Jenkins Scriptler Plugin 3.3 and earlier does not escape the name of scripts on the UI when asking to confirm their deletion, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by exploitable by attackers able to cr…
- CVE-2023-50764HIGHCVSS 8.1EG 8.12023-12-13
vulnerable: 2.0 ... 338.v7b_33a_7e18d4b_ (23 versions)
Jenkins Scriptler Plugin 342.v6a_89fd40f466 and earlier does not restrict a file name query parameter in an HTTP endpoint, allowing attackers with Scriptler/Configure permission to delete arbitrary files on the Jenkins controller file syst…
- CVE-2023-50765MEDIUMCVSS 4.3EG 4.32023-12-13
vulnerable: 2.0 ... 338.v7b_33a_7e18d4b_ (23 versions)
A missing permission check in Jenkins Scriptler Plugin 342.v6a_89fd40f466 and earlier allows attackers with Overall/Read permission to read the contents of a Groovy script by knowing its ID.
Check whether org.jenkins-ci.plugins:scriptler is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.jenkins-ci.plugins:scriptler CVEs against the assets you own.
Start Free Scan →