Vulnerabilities (CVE)

Filtered by vendor Jenkins Subscribe
Filtered by product Filesystem List Parameter
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-54004 1 Jenkins 1 Filesystem List Parameter 2025-10-03 N/A 4.3 MEDIUM
Jenkins Filesystem List Parameter Plugin 0.0.14 and earlier does not restrict the path used for the File system objects list Parameter, allowing attackers with Item/Configure permission to enumerate file names on the Jenkins controller file system.
CVE-2022-34187 1 Jenkins 1 Filesystem List Parameter 2024-11-21 3.5 LOW 5.4 MEDIUM
Jenkins Filesystem List Parameter Plugin 0.0.7 and earlier does not escape the name and description of File system objects list parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.