[MAVEN:GHSA-6Q4P-JRJV-44GF] Cross-site request forgery vulnerability in Jenkins XL TestView Plugin

Severity High
Affected Packages 1
CVEs 1

A cross-site request forgery vulnerability in Jenkins XL TestView Plugin 1.2.0 and earlier in XLTestView.XLTestDescriptor#doTestConnection allows users with Overall/Read access to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

Package Affected Version
pkg:maven/com.xebialabs.xlt.ci/xltestview-plugin <= 1.2.0
ID
MAVEN:GHSA-6Q4P-JRJV-44GF
Severity
high
URL
https://github.com/advisories/GHSA-6q4p-jrjv-44gf
Published
2022-05-24T16:52:46
(2 years ago)
Modified
2024-01-30T23:18:53
(7 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/com.xebialabs.xlt.ci/xltestview-plugin com.xebialabs.xlt.ci xltestview-plugin <= 1.2.0
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...