VYPR

Rqm

by Jenkins Project

CVEs (3)

  • CVE-2022-41241CriSep 21, 2022
    risk 0.59cvss 9.1epss 0.01

    Jenkins RQM Plugin 2.8 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.

  • CVE-2022-34810MedJun 30, 2022
    risk 0.42cvss 6.5epss 0.01

    A missing check in Jenkins RQM Plugin 2.8 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2022-34809MedJun 30, 2022
    risk 0.42cvss 6.5epss 0.01

    Jenkins RQM Plugin 2.8 and earlier stores a password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with access to the Jenkins controller file system.