Skip to main content

Vendor/product archive

jenkins / git_parameter CVEs

Beta · best-effort

6 CVEs tagged to jenkins / git_parameter0 Critical, 1 High, 5 Medium, 0 Low, 0 Unrated.

CVE-2026-57286

Published Jun 24, 2026

A missing permission check in Jenkins Git Parameter Plugin 462.vdcf3df2ed2ca_ and earlier allows attackers with Item/Read permission to obtain information about the SCM repository…

CVSS 4.3 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2025-53652

Published Jul 9, 2025

Jenkins Git Parameter Plugin 439.vb_0e46ca_14534 and earlier does not validate that the Git parameter value submitted to the build matches one of the offered choices, allowing att…

CVSS 8.2 · High
Vendor/product tagsBeta · best-effort

CVE-2022-29040

Published Apr 12, 2022

Jenkins Git Parameter Plugin 0.9.15 and earlier does not escape the name and description of Git parameters on views displaying parameters, resulting in a stored cross-site scripti…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2238

Published Sep 1, 2020

Jenkins Git Parameter Plugin 0.9.12 and earlier does not escape the repository field on the 'Build with Parameters' page, resulting in a stored cross-site scripting (XSS) vulnerab…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2113

Published Feb 12, 2020

Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the default value shown on the UI, resulting in a stored cross-site scripting vulnerability exploitable by users wi…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2112

Published Feb 12, 2020

Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the parameter name shown on the UI, resulting in a stored cross-site scripting vulnerability exploitable by users w…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-6 of 6 CVEsPage 1 of 1