Ns Nd Integration Performance Publisher
ns-nd_integration_performance_publisher
Vendor: Jenkins • 8 CVEs
CVEs (8)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Jenkins 1Ns Nd Integration Performance Publisher Jun 17, 2026 May 16, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.149 and earlier does not mask credentials displayed on the configuration form, increasing the potential for attackers to observe and capture them. |
1Jenkins 1Ns Nd Integration Performance Publisher Jun 17, 2026 Nov 15, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by attackers with Extended Read permiss...Show more |
1Jenkins 1Ns Nd Integration Performance Publisher Jun 17, 2026 Nov 15, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier globally and unconditionally disables SSL/TLS certificate and hostname validation for the entire Jenkins controller JVM. |
1Jenkins 1Ns Nd Integration Performance Publisher Jun 17, 2026 Nov 15, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.146 and earlier unconditionally disables SSL/TLS certificate and hostname validation for several features. |
1Jenkins 1Ns Nd Integration Performance Publisher Jun 17, 2026 Sep 21, 2022 N/A· v4 5.4 MEDIUM· v3 N/A· v2 Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.134 and earlier does not escape configuration options of the Execute NetStorm/NetCloud Test build step, resulting in a stored cross-site scripting (XSS) vulner...Show more |
1Jenkins 1Ns Nd Integration Performance Publisher Jun 17, 2026 Sep 21, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A missing permission check in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers with Overall/Read permissions to connect to an attacker-specified webserver using attacker-speci...Show more |
1Jenkins 1Ns Nd Integration Performance Publisher Jun 17, 2026 Sep 21, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A cross-site request forgery (CSRF) vulnerability in Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.129 and earlier allows attackers to connect to an attacker-specified webserver using attacker-specified cr...Show more |
1Jenkins 1Ns Nd Integration Performance Publisher Jun 17, 2026 Jun 23, 2022 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.77 and earlier does not escape the name of NetStorm Test parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerabil...Show more |