QID 994967

Date Published: 2023-08-23

QID 994967: Java (Maven) Security Update for org.jenkins-ci.plugins:fortify (GHSA-223m-pgcq-f3xg)

Jenkins Fortify Plugin 22.1.38 and earlier does not escape the error message for a form validation method. This results in an HTML injection vulnerability.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Medium - 4.3 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution
    Refer to Github security advisory GHSA-223m-pgcq-f3xg for updates and patch information.
    Vendor References

    CVEs related to QID 994967

    Software Advisories
    Advisory ID Software Component Link
    GHSA-223m-pgcq-f3xg org.jenkins-ci.plugins:fortify URL Logo github.com/advisories/GHSA-223m-pgcq-f3xg