VendorsJenkinsbumblebee_hp_almany version
Vulnerabilities

Jenkins Bumblebee HP ALM any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

2CVEs
CVE-2019-10444
Jenkins Bumblebee HP ALM Plugin 4.1.3 and earlier unconditionally disabled SSL/TLS and hostname verification for connections to HP ALM.
Published 2019-10-16 · Modified
6.5EPSS 0.008
CVE-2021-21614
Jenkins Bumblebee HP ALM Plugin 4.1.5 and earlier stores credentials unencrypted in its global configuration file on the Jenkins controller where they can be viewed by users with access to the Jenkins controller file system.
Published 2021-01-13 · Modified
5.5EPSS 0.003