Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Jenkins Subscribe
Filtered by product Cobertura
Total 2 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2020-2138 1 Jenkins 1 Cobertura 2020-03-10 5.5 MEDIUM 7.1 HIGH
Jenkins Cobertura Plugin 1.15 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
CVE-2020-2139 1 Jenkins 1 Cobertura 2020-03-09 8.5 HIGH 6.5 MEDIUM
An arbitrary file write vulnerability in Jenkins Cobertura Plugin 1.15 and earlier allows attackers able to control the coverage report file contents to overwrite any file on the Jenkins master file system.