[MAVEN:GHSA-F799-HFG3-48JP] Stored XSS vulnerability in Jenkins Sonargraph Integration Plugin

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

Sonargraph Integration Plugin 3.0.0 and earlier does not escape the file path for the Log file field form validation.

This results in a stored cross-site scripting (XSS) vulnerability that can be exploited by users with Job/Configure permission.

Sonargraph Integration Plugin 3.0.1 escapes the affected part of the error message.

ID
MAVEN:GHSA-F799-HFG3-48JP
Severity
moderate
URL
https://github.com/advisories/GHSA-f799-hfg3-48jp
Published
2022-05-24T17:22:18
(2 years ago)
Modified
2023-01-28T05:06:13
(19 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.plugins/sonargraph-integration org.jenkins-ci.plugins sonargraph-integration <= 3.0.0
Fixed pkg:maven/org.jenkins-ci.plugins/sonargraph-integration org.jenkins-ci.plugins sonargraph-integration = 3.0.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...