org.jenkins-ci.plugins:zephyr-enterprise-test-management
Maven3 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting org.jenkins-ci.plugins:zephyr-enterprise-test-managementpage 1 of 1
- CVE-2019-1003084MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.82019-04-04
vulnerable: 1.0 ... 1.6 (7 versions)
A cross-site request forgery vulnerability in Jenkins Zephyr Enterprise Test Management Plugin in the ZeeDescriptor#doTestConnection form validation method allows attackers to initiate a connection to an attacker-specified server.
- CVE-2019-1003085MEDIUMCVSS 6.5EG 6.5✓ Fixed in 1.82019-04-04
vulnerable: 1.0 ... 1.6 (7 versions)
A missing permission check in Jenkins Zephyr Enterprise Test Management Plugin in the ZeeDescriptor#doTestConnection form validation method allows attackers with Overall/Read permission to initiate a connection to an attacker-specified ser…
- CVE-2020-2145MEDIUMCVSS 5.5EG 5.5✓ Fixed in 1.102020-03-09
vulnerable: 1.0 ... 1.9.1 (10 versions)
Jenkins Zephyr Enterprise Test Management Plugin 1.9.1 and earlier stores its Zephyr password in plain text on the Jenkins master file system.
Check whether org.jenkins-ci.plugins:zephyr-enterprise-test-management is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for org.jenkins-ci.plugins:zephyr-enterprise-test-management CVEs against the assets you own.
Start Free Scan →