VYPR

MSTest Plugin

by Jenkins Project

Source repositories

CVEs (6)

  • CVE-2023-24441Jan 24, 2023
    risk 0.00cvss epss 0.02

    Jenkins MSTest Plugin 1.0.0 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2022-41243Sep 21, 2022
    risk 0.00cvss epss 0.00

    Jenkins SmallTest Plugin 1.0.4 and earlier does not perform hostname validation when connecting to the configured View26 server that could be abused using a man-in-the-middle attack to intercept these connections.

  • CVE-2020-2273Sep 16, 2020
    risk 0.00cvss epss 0.00

    A cross-site request forgery (CSRF) vulnerability in Jenkins ElasTest Plugin 1.2.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials.

  • CVE-2020-2274Sep 16, 2020
    risk 0.00cvss epss 0.00

    Jenkins ElasTest Plugin 1.2.1 and earlier stores its server password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.

  • CVE-2020-2272Sep 16, 2020
    risk 0.00cvss epss 0.00

    A missing permission check in Jenkins ElasTest Plugin 1.2.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials.

  • CVE-2020-2129Feb 12, 2020
    risk 0.00cvss epss 0.00

    Jenkins Eagle Tester Plugin 1.0.9 and earlier stores a password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system.