'JMeter performance plugin having XXE vulnerability. Any other alternatives?
JMeter performance plugin is listed with vulnerability: https://plugins.jenkins.io/performance/ So currently its not safe to use this plugin(https://www.jenkins.io/security/advisory/2021-11-12/#SECURITY-2394).
Anyone have other alternatives for JMeter test reporting using Jenkins? Or do we have any other solution to fix this vulnerability and still use this performance plugin? Screenshot of Performance Plugin
Solution 1:[1]
The plugin is open source so you're welcome to contribute the fix via pull request
If you're a BlazeMeter customer you can request the fix via BlazeMeter Support
Sources
This article follows the attribution requirements of Stack Overflow and is licensed under CC BY-SA 3.0.
Source: Stack Overflow
Solution | Source |
---|---|
Solution 1 | Dmitri T |