Search Results (2 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2024-54004 1 Jenkins 1 Filesystem List Parameter 2025-10-03 4.3 Medium
Jenkins Filesystem List Parameter Plugin 0.0.14 and earlier does not restrict the path used for the File system objects list Parameter, allowing attackers with Item/Configure permission to enumerate file names on the Jenkins controller file system.
CVE-2022-34187 1 Jenkins 1 Filesystem List Parameter 2024-11-21 5.4 Medium
Jenkins Filesystem List Parameter Plugin 0.0.7 and earlier does not escape the name and description of File system objects list parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.