Skip to main content

Vendor/product archive

jenkins / junit CVEs

Beta · best-effort

5 CVEs tagged to jenkins / junit0 Critical, 1 High, 4 Medium, 0 Low, 0 Unrated.

CVE-2023-25761

Published Feb 15, 2023

Jenkins JUnit Plugin 1166.va_436e268e972 and earlier does not escape test case class names in JavaScript expressions, resulting in a stored cross-site scripting (XSS) vulnerabilit…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-45380

Published Nov 15, 2022

Jenkins JUnit Plugin 1159.v0b_396e1e07dd and earlier converts HTTP(S) URLs in test report output to clickable links in an unsafe manner, resulting in a stored cross-site scripting…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-34176

Published Jun 23, 2022

Jenkins JUnit Plugin 1119.va_a_5e9068da_d7 and earlier does not escape descriptions of test results, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by…

CVSS 5.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000411

Published Jan 9, 2019

A cross-site request forgery vulnerability exists in Jenkins JUnit Plugin 1.25 and earlier in TestObject.java that allows setting the description of a test result.

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2018-1000056

Published Feb 9, 2018

Jenkins JUnit Plugin 1.23 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extra…

CVSS 8.3 · High
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1