QID 996927

Date Published: 2024-01-30

QID 996927: Java (Maven) Security Update for org.jenkins-ci.plugins:config-file-provider (GHSA-vwfm-42q6-qj75)

A cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.1 and earlier in configfiles.jelly, providerlist.jelly that allows users with the ability to configure configuration files to insert arbitrary HTML into some pages in Jenkins.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Medium - 5.4 severity.
  • CVSS V2 rated as Medium - 3.5 severity.
  • Solution
    Refer to Github security advisory GHSA-vwfm-42q6-qj75 for updates and patch information.
    Vendor References

    CVEs related to QID 996927

    Software Advisories
    Advisory ID Software Component Link
    GHSA-vwfm-42q6-qj75 org.jenkins-ci.plugins:config-file-provider URL Logo github.com/advisories/GHSA-vwfm-42q6-qj75