Vulnerabilities (CVE)

Filtered by vendor Jenkins Subscribe
Filtered by product Maven Metadata
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-36905 1 Jenkins 1 Maven Metadata 2024-11-21 N/A 5.4 MEDIUM
Jenkins Maven Metadata Plugin for Jenkins CI server Plugin 2.2 and earlier does not perform URL validation for the Repository Base URL of List maven artifact versions parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
CVE-2022-34190 1 Jenkins 1 Maven Metadata 2024-11-21 3.5 LOW 5.4 MEDIUM
Jenkins Maven Metadata Plugin for Jenkins CI server Plugin 2.1 and earlier does not escape the name and description of List maven artifact versions parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.