Qmetry develops a Jenkins plugin for test management integration with Jira that brings quality automation into development workflows; its narrow vulnerability footprint concentrates in this specialized plugin. The durable signal is rooted in credential and data-transmission handling, with recurring issues around cleartext transmission of sensitive information and insufficiently protected credentials. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Qmetry over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-16544HIGH Jenkins QMetry for JIRA - Test Management Plugin 1.12 and earlier stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users wit | Nov 21, 2019 | 8.8 | 27 | NO | NO |
CVE-2019-16545MEDIUM Jenkins QMetry for JIRA - Test Management Plugin transmits credentials in its configuration in plain text as part of job configuration forms, potentially resulting in their exposur | Nov 21, 2019 | 6.5 | 21 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Qmetry.
Media articles that mention a CVE ID that affects a product developed by Qmetry — matched by CVE ID, not by vendor name.