threatengine.sh
· ··:··
Sign in
free plan Dashboard Stack Monitoring Notifications Watchlist Account & tokens API docs Pricing Sign out
Home/Product/jenkins junit
Product

jenkins junit

6 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
CVE-2023-25761
<= 1166.va_436e268e972
Jenkins JUnit Plugin 1166.va_436e268e972 and earlier does not escape test case class names in JavaScript expressions, resulting in
5.4MEDIUM
CVE-2022-45380
< 1160.vf1f01a_a_ea_b_7f
Jenkins JUnit Plugin 1159.v0b_396e1e07dd and earlier converts HTTP(S) URLs in test report output to clickable links in an unsafe m
5.4MEDIUM
CVE-2022-34176
<= 1119.va_a_5e9068da_d7
Jenkins JUnit Plugin 1119.va_a_5e9068da_d7 and earlier does not escape descriptions of test results, resulting in a stored cross-s
5.4MEDIUM
CVE-2020-15250
>= 4.7 and < 4.13.1
In JUnit4 from version 4.7 and before 4.13.1, the test rule TemporaryFolder contains a local information disclosure vulnerability.
4.4MEDIUM
CVE-2018-1000411
<= 1.25
A cross-site request forgery vulnerability exists in Jenkins JUnit Plugin 1.25 and earlier in TestObject.java that allows setting
6.5MEDIUM
CVE-2018-1000056
<= 1.23
Jenkins JUnit Plugin 1.23 and earlier processes XML external entities in files it parses as part of the build process, allowing at
8.3HIGH
SOC and Response
CVE triage
Stack monitoring
Am I affected
IOC triage
KEV catalog
Recently exploited
Daily brief
Change tracking
Detection Engineering
Detection coverage workspace
Saved stacks
SIEM query builder
Detection rules
D3FEND
Threat Hunting
Threat actors
ATT&CK techniques
Attack paths
Indicators
Ransomware groups
Atomic tests
Red Team and Pentest
Exploitability triage
Recon pack
Attack paths
CAPEC patterns
Adversary emulation
Compliance and GRC
Framework mapping
Control assessment
Audit view
Atlas Search Threat actors Techniques Detection coverage Tools & malware CWE CAPEC KEV catalog Package vulns
About All capabilities Pricing API docs Privacy policy Terms of service
threatengine.sh
Are you sure?
We use one first-party cookie to remember how you found us, only if you allow it. Everything the site needs to work uses essential cookies. See our privacy policy.