QID 995968
Date Published: 2023-11-20
QID 995968: Java (Maven) Security Update for com.paul8620.jenkins.plugins:pipeline-aggregator-view (GHSA-jf8x-943c-r4h6)
Jenkins Pipeline Aggregator View Plugin 1.8 and earlier does not escape information shown on its view, resulting in a stored XSS vulnerability exploitable by attackers able to affects view content such as job display name or pipeline stage names.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-jf8x-943c-r4h6 for updates and patch information.
Vendor References
- GHSA-jf8x-943c-r4h6 -
github.com/advisories/GHSA-jf8x-943c-r4h6
CVEs related to QID 995968
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-jf8x-943c-r4h6 | com.paul8620.jenkins.plugins:pipeline-aggregator-view |
|