Vulnerability GHSA-hvcr-927w-qcvq
High Risk
HIGH RISK
CVSS Score: 7.5
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
3 years ago
October 19, 2022 at 07:00 PM UTC
Stored XSS vulnerability in Jenkins Contrast Continuous Application Security Plugin
1.0.0 - 1.4.0 and 1.6.0 - 3.7.0 and 3.9.0
1.0.0 - 1.4.0 and 1.6.0 - 3.7.0 and 3.9.0
Summary
Stored XSS vulnerability in Jenkins Contrast Continuous Application Security Plugin
Details
Contrast Continuous Application Security Plugin 3.9 and earlier does not escape data returned from the Contrast service when generating a report.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control or modify Contrast service API responses.
Contrast Continuous Application Security Plugin 3.10 escapes the affected data.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
3 months ago
Jenkins Contrast Continuous Application Security Plugin has a CSRF vulnerability
1.0.0 - 1.4.0 and 1.6.0 - 3.7.0 and 3.9.0 - 3.11.0 GHSA-6qc4-57v3-28rr
1.0.0 - 1.4.0 and 1.6.0 - 3.7.0 and 3.9.0 - 3.11.0 GHSA-6qc4-57v3-28rr
Medium Risk
3 months ago
Jenkins Contrast Continuous Application Security Plugin missing permission checks
1.0.0 - 1.4.0 and 1.6.0 - 3.7.0 and 3.9.0 - 3.11.0 GHSA-8263-qv4g-vfxr
1.0.0 - 1.4.0 and 1.6.0 - 3.7.0 and 3.9.0 - 3.11.0 GHSA-8263-qv4g-vfxr
Medium Risk
3 months ago
Jenkins Contrast Continuous Application Security Plugin has a missing permission check
1.0.0 - 1.4.0 and 1.6.0 - 3.7.0 and 3.9.0 - 3.11.0 GHSA-p44q-fmwr-jqr7
1.0.0 - 1.4.0 and 1.6.0 - 3.7.0 and 3.9.0 - 3.11.0 GHSA-p44q-fmwr-jqr7
Impacted packages
Timeline
Published
3 years ago
October 19, 2022 at 07:00 PM UTC
Last Modified
2 years ago
February 16, 2024 at 08:17 AM UTC