Vulnerabilities > Jenkins > Spira Importer

DATE CVE VULNERABILITY TITLE RISK
2019-12-17 CVE-2019-16558 Improper Certificate Validation vulnerability in Jenkins Spira Importer 3.2.2/3.2.3
Jenkins Spira Importer Plugin 3.2.3 and earlier disables SSL/TLS certificate validation for the Jenkins master JVM.
network
low complexity
jenkins CWE-295
8.2
2019-11-21 CVE-2019-16543 Insufficiently Protected Credentials vulnerability in Jenkins Spira Importer 3.2.2
Jenkins Spira Importer Plugin 3.2.2 and earlier stores credentials unencrypted in its global configuration file on the Jenkins master where they can be viewed by users with access to the master file system.
local
low complexity
jenkins CWE-522
5.5