Vulnerabilities > Jenkins > Tests Selector > 1.3

DATE CVE VULNERABILITY TITLE RISK
2022-03-29 CVE-2022-28159 Cross-site Scripting vulnerability in Jenkins Tests Selector
Jenkins Tests Selector Plugin 1.3.3 and earlier does not escape the Properties File Path option for Choosing Tests parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
network
low complexity
jenkins CWE-79
5.4
2022-03-29 CVE-2022-28160 Exposure of Resource to Wrong Sphere vulnerability in Jenkins Tests Selector
Jenkins Tests Selector Plugin 1.3.3 and earlier allows users with Item/Configure permission to read arbitrary files on the Jenkins controller.
network
low complexity
jenkins CWE-668
6.5