[JENKINS:SECURITY-1118] Stored XSS vulnerability in `build-metrics`

Severity High
Affected Packages 2
CVEs 1

build-metrics 1.3 does not escape the build description on one of its views.

This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Build/Update permission.

As of publication of this advisory, there is no fix.

ID
JENKINS:SECURITY-1118
Severity
high
Published
2022-06-30T00:00:00
(2 years ago)
Modified
2022-06-30T00:00:00
(2 years ago)
Rights
Jenkins Security Team
Other Advisories
Source # ID Name URL
Plugin repository build-metrics repository https://github.com/jenkinsci/build-metrics-plugin
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.plugins/build-metrics org.jenkins-ci.plugins build-metrics <= 1.3
Affected pkg:github/jenkinsci/build-metrics-plugin jenkinsci build-metrics-plugin <= 1.3
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...