cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2019-10387,https://securityvulnerability.io/vulnerability/CVE-2019-10387,,"A missing permission check in Jenkins XL TestView Plugin 1.2.0 and earlier in XLTestView.XLTestDescriptor#doTestConnection allows users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.",Jenkins,Jenkins Xl Testview Plugin,6.5,MEDIUM,0.000699999975040555,false,,false,false,false,,,false,false,,2019-08-07T14:20:25.000Z,0 CVE-2019-10386,https://securityvulnerability.io/vulnerability/CVE-2019-10386,,"A cross-site request forgery vulnerability in Jenkins XL TestView Plugin 1.2.0 and earlier in XLTestView.XLTestDescriptor#doTestConnection allows users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.",Jenkins,Jenkins Xl Testview Plugin,8.8,HIGH,0.000910000002477318,false,,false,false,false,,,false,false,,2019-08-07T14:20:24.000Z,0