QID 983814
QID 983814: Java (maven) Security Update for org.jenkins-ci.plugins:kiuwanJenkinsPlugin (GHSA-8h77-3xwr-hqhh)
Jenkins Kiuwan Plugin 1.6.0 and earlier does not escape query parameters in an error message for a form validation endpoint, resulting in a reflected cross-site scripting (XSS) vulnerability.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-8h77-3xwr-hqhh for updates pertaining to this vulnerability.
Vendor References
- GHSA-8h77-3xwr-hqhh -
github.com/advisories/GHSA-8h77-3xwr-hqhh
CVEs related to QID 983814
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-8h77-3xwr-hqhh | org.jenkins-ci.plugins:kiuwanJenkinsPlugin |
|