Jenkins / Code Coverage Api
3 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2021-21677 | Jenkins Code Coverage API Plugin 1.4.0 and earlier does not apply Jenkins JEP-200 deserialization protection to Java objects it deserializes from disk, resulti… | HIGH | 8.8 | Aug 31, 2021 |
| CVE-2020-2172 | Jenkins Code Coverage API Plugin 1.1.4 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | MEDIUM | 6.5 | Apr 7, 2020 |
| CVE-2020-2106 | Jenkins Code Coverage API Plugin 1.1.2 and earlier does not escape the filename of the coverage report used in its view, resulting in a stored XSS vulnerabilit… | MEDIUM | 5.4 | Jan 29, 2020 |
Showing 1 to 3 of 3 CVEs