Vulnerabilities > Jenkins > XL Testview > 1.2.0

DATE CVE VULNERABILITY TITLE RISK
2019-08-07 CVE-2019-10387 Missing Authorization vulnerability in Jenkins XL Testview
A missing permission check in Jenkins XL TestView Plugin 1.2.0 and earlier in XLTestView.XLTestDescriptor#doTestConnection allows users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
network
low complexity
jenkins CWE-862
6.5
2019-08-07 CVE-2019-10386 Cross-Site Request Forgery (CSRF) vulnerability in Jenkins XL Testview
A cross-site request forgery vulnerability in Jenkins XL TestView Plugin 1.2.0 and earlier in XLTestView.XLTestDescriptor#doTestConnection allows users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.
network
low complexity
jenkins CWE-352
8.8