[MAVEN:GHSA-QMF3-W5JF-CV54] XSS vulnerability in Jenkins Subversion Partial Release Manager Plugin

Severity Moderate
Affected Packages 1
CVEs 1

Subversion Partial Release Manager Plugin 1.0.1 and earlier does not escape the error message for the repository URL field form validation.

This results in a reflected cross-site scripting (XSS) vulnerability that can also be exploited similar to a stored cross-site scripting vulnerability by users with Job/Configure permission.

ID
MAVEN:GHSA-QMF3-W5JF-CV54
Severity
moderate
URL
https://github.com/advisories/GHSA-qmf3-w5jf-cv54
Published
2022-05-24T17:19:05
(2 years ago)
Modified
2023-01-29T05:07:11
(19 months ago)
Rights
Maven Security Team
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.plugins/svn-partial-release-mgr org.jenkins-ci.plugins svn-partial-release-mgr <= 1.0.1
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...