VYPR

Tests Selector

by Jenkins Project

CVEs (2)

  • CVE-2022-28160MedMar 29, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins Tests Selector Plugin 1.3.3 and earlier allows users with Item/Configure permission to read arbitrary files on the Jenkins controller.

  • CVE-2022-28159MedMar 29, 2022
    risk 0.35cvss 5.4epss 0.01

    Jenkins Tests Selector Plugin 1.3.3 and earlier does not escape the Properties File Path option for Choosing Tests parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.