Skip to main content

Vendor/product archive

jenkins / elastest CVEs

Beta · best-effort

3 CVEs tagged to jenkins / elastest0 Critical, 0 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2020-2274

Published Sep 16, 2020

Jenkins ElasTest Plugin 1.2.1 and earlier stores its server password unencrypted in its global configuration file on the Jenkins controller where it can be viewed by users with ac…

CVSS 5.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2273

Published Sep 16, 2020

A cross-site request forgery (CSRF) vulnerability in Jenkins ElasTest Plugin 1.2.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified cr…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-2272

Published Sep 16, 2020

A missing permission check in Jenkins ElasTest Plugin 1.2.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specif…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1