de.tracetronic.jenkins.plugins:ecutest
Maven3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting de.tracetronic.jenkins.plugins:ecutestpage 1 of 1
- CVE-2018-1999025HIGHCVSS 7.4EG 7.4✓ Fixed in 2.42018-08-01
vulnerable: 1.0 ... 2.3 (24 versions)
A man in the middle vulnerability exists in Jenkins TraceTronic ECU-TEST Plugin 2.3 and earlier in ATXPublisher.java, ATXValidator.java that allows attackers to impersonate any service that Jenkins connects to.
- CVE-2018-1999026MEDIUMCVSS 6.5EG 6.5✓ Fixed in 2.42018-08-01
vulnerable: 1.0 ... 2.3 (24 versions)
A server-side request forgery vulnerability exists in Jenkins TraceTronic ECU-TEST Plugin 2.3 and earlier in ATXPublisher.java that allows attackers to have Jenkins send HTTP requests to an attacker-specified host.
- CVE-2021-21612MEDIUMCVSS 5.5EG 5.5✓ Fixed in 2.242021-01-13
vulnerable: 1.0 ... 2.9 (45 versions)
Jenkins TraceTronic ECU-TEST Plugin 2.23.1 and earlier stores credentials unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
Check whether de.tracetronic.jenkins.plugins:ecutest is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for de.tracetronic.jenkins.plugins:ecutest CVEs against the assets you own.
Start Free Scan →