JMeter性能插件存在XXE漏洞。还有其他选择吗?
JMeter 性能插件列出了漏洞:https://plugins.jenkins.io/performance/ 所以目前使用这个插件并不安全(https:/ /www.jenkins.io/security/advisory/2021-11-12/#SECURITY-2394)。
有人有使用 Jenkins 进行 JMeter 测试报告的其他替代方案吗?或者我们有其他解决方案来修复这个漏洞并且仍然使用这个性能插件吗? 性能插件屏幕截图
JMeter performance plugin is listed with vulnerability: https://plugins.jenkins.io/performance/
So currently its not safe to use this plugin(https://www.jenkins.io/security/advisory/2021-11-12/#SECURITY-2394).
Anyone have other alternatives for JMeter test reporting using Jenkins? Or do we have any other solution to fix this vulnerability and still use this performance plugin?
Screenshot of Performance Plugin
如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

绑定邮箱获取回复消息
由于您还没有绑定你的真实邮箱,如果其他用户或者作者回复了您的评论,将不能在第一时间通知您!
发布评论
评论(2)
该插件是开源,因此欢迎您通过拉取请求
如果您是 BlazeMeter 客户,您可以通过 BlazeMeter 支持
The plugin is open source so you're welcome to contribute the fix via pull request
If you're a BlazeMeter customer you can request the fix via BlazeMeter Support
该修复已在存储库中,但新版本尚未构建并部署到 Jenkins。这是开源社区无法做到的。
https://github.com/jenkinsci/performance-plugin/pull/205/commits/8f94845417cfa0089f5b1fea3a5b8d09d7f333d0
The fix is already in repo, but the new version is not built and deployed to Jenkins. This cannot be done by open source community.
https://github.com/jenkinsci/performance-plugin/pull/205/commits/8f94845417cfa0089f5b1fea3a5b8d09d7f333d0