[MAVEN:GHSA-2PC2-H97H-2MMW] Jenkins iceScrum Plugin vulnerable to stored Cross-site Scripting

Severity High
Affected Packages 1
CVEs 1

Jenkins iceScrum Plugin 1.1.6 and earlier does not sanitize iceScrum project URLs on build views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs.

Package Affected Version
pkg:maven/org.jenkins-ci.plugins/icescrum <= 1.1.6
ID
MAVEN:GHSA-2PC2-H97H-2MMW
Severity
high
URL
https://github.com/advisories/GHSA-2pc2-h97h-2mmw
Published
2024-03-06T18:30:39
(6 months ago)
Modified
2024-03-06T20:13:57
(6 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.plugins/icescrum org.jenkins-ci.plugins icescrum <= 1.1.6
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...