Jenkins / Elastest
3 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2020-2274 | Jenkins ElasTest Plugin 1.2.1 and earlier stores its server password unencrypted in its global configuration file on the Jenkins controller where it can be vie… | MEDIUM | 5.5 | Sep 16, 2020 |
| CVE-2020-2273 | A cross-site request forgery (CSRF) vulnerability in Jenkins ElasTest Plugin 1.2.1 and earlier allows attackers to connect to an attacker-specified URL using a… | MEDIUM | 4.3 | Sep 16, 2020 |
| CVE-2020-2272 | A missing permission check in Jenkins ElasTest Plugin 1.2.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL u… | MEDIUM | 4.3 | Sep 16, 2020 |
Showing 1 to 3 of 3 CVEs