VYPR

Maven package

com.soasta.jenkins/cloudtest

pkg:maven/com.soasta.jenkins/cloudtest

Vulnerabilities (3)

  • CVE-2019-10451Oct 16, 2019
    affected <= 2.25

    Jenkins SOASTA CloudTest Plugin stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.

  • CVE-2019-1003091Apr 4, 2019
    affected <= 2.25

    A missing permission check in Jenkins SOASTA CloudTest Plugin in the CloudTestServer.DescriptorImpl#doValidate form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.

  • CVE-2019-1003090Apr 4, 2019
    affected <= 2.25

    A cross-site request forgery vulnerability in Jenkins SOASTA CloudTest Plugin in the CloudTestServer.DescriptorImpl#doValidate form validation method allows attackers to initiate a connection to an attacker-specified server.