org.kohsuke.stapler:stapler-parent
Maven3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.kohsuke.stapler:stapler-parentpage 1 of 1
- CVE-2018-1000997MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.250.22019-01-23
vulnerable: 1.100 ... 1.99 (149 versions)
A path traversal vulnerability exists in the Stapler web framework used by Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/org/kohsuke/stapler/Facet.java, groovy/src/main/java/org/kohsuke/stapler/jelly/groovy/Groov…
- CVE-2018-1999007MEDIUMCVSS 5.4EG 5.4✓ Fixed in 1.250.12018-07-23
vulnerable: 1.100 ... 1.99 (148 versions)
A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers with the ability to control the existence of some URLs in J…
- CVE-2019-10354MEDIUMCVSS 4.3EG 4.3✓ Fixed in 1.257.12019-07-17
vulnerable: 1.100 ... 1.99 (162 versions)
A vulnerability in the Stapler web framework used in Jenkins 2.185 and earlier, LTS 2.176.1 and earlier allowed attackers to access view fragments directly, bypassing permission checks and possibly obtain sensitive information.
Check whether org.kohsuke.stapler:stapler-parent is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.kohsuke.stapler:stapler-parent CVEs against the assets you own.
Start Free Scan →