Total
2 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-46682 | 1 Jenkins | 1 Plot | 2024-11-21 | N/A | 9.8 CRITICAL |
Jenkins Plot Plugin 2.1.11 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |||||
CVE-2022-34783 | 1 Jenkins | 1 Plot | 2024-11-21 | 3.5 LOW | 5.4 MEDIUM |
Jenkins Plot Plugin 2.1.10 and earlier does not escape plot descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. |