Vulnerability GHSA-fgxc-mxvw-55mv
Medium Risk
MEDIUM RISK
CVSS Score: 5.4
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
4 years ago
May 24, 2022 at 05:08 PM UTC
Jenkins Git Parameter Plugin vulnerable to stored cross-site scripting (XSS)
0.4.0 - 0.5.1 and 0.8.0 - 0.8.1
0.4.0 - 0.5.1 and 0.8.0 - 0.8.1
Summary
Jenkins Git Parameter Plugin vulnerable to stored cross-site scripting (XSS)
Details
Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the default value shown on the UI, resulting in a stored cross-site scripting vulnerability exploitable by users with Job/Configure permission.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
3 months ago
Jenkins Git Parameter Plugin has a missing permission check that allows listing SCM branch and tag names
0.4.0 - 0.5.1 and 0.8.0 - 0.8.1 and 0.10.0 - 0.11.0 GHSA-hwvp-7xqv-8jx3
0.4.0 - 0.5.1 and 0.8.0 - 0.8.1 and 0.10.0 - 0.11.0 GHSA-hwvp-7xqv-8jx3
Medium Risk
1 year ago
Jenkins Git Parameter Plugin vulnerable to code injection due to inexhaustive parameter check
0.4.0 - 0.5.1 and 0.8.0 - 0.8.1 and 0.10.0 - 0.11.0 GHSA-qcj2-99cg-mppf
0.4.0 - 0.5.1 and 0.8.0 - 0.8.1 and 0.10.0 - 0.11.0 GHSA-qcj2-99cg-mppf
High Risk
4 years ago
Stored XSS vulnerability in Jenkins Git Parameter Plugin
0.4.0 - 0.5.1 and 0.8.0 - 0.8.1 GHSA-j7q2-c6r4-x2jw
0.4.0 - 0.5.1 and 0.8.0 - 0.8.1 GHSA-j7q2-c6r4-x2jw
Medium Risk
4 years ago
Jenkins Git Parameter Plugin vulnerable to Stored cross-site scripting (XSS)
0.4.0 - 0.5.1 and 0.8.0 - 0.8.1 GHSA-hw26-fw67-qxm9
0.4.0 - 0.5.1 and 0.8.0 - 0.8.1 GHSA-hw26-fw67-qxm9
Medium Risk
4 years ago
Stored XSS vulnerability in Jenkins Git Parameter Plugin
0.4.0 - 0.5.1 and 0.8.0 - 0.8.1 GHSA-fcr6-6cph-vmcm
0.4.0 - 0.5.1 and 0.8.0 - 0.8.1 GHSA-fcr6-6cph-vmcm
Impacted packages
Timeline
Published
4 years ago
May 24, 2022 at 05:08 PM UTC
Last Modified
2 years ago
February 16, 2024 at 07:56 AM UTC