QID 996927
Date Published: 2024-01-30
QID 996927: Java (Maven) Security Update for org.jenkins-ci.plugins:config-file-provider (GHSA-vwfm-42q6-qj75)
A cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.1 and earlier in configfiles.jelly, providerlist.jelly that allows users with the ability to configure configuration files to insert arbitrary HTML into some pages in Jenkins.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-vwfm-42q6-qj75 for updates and patch information.
Vendor References
- GHSA-vwfm-42q6-qj75 -
github.com/advisories/GHSA-vwfm-42q6-qj75
CVEs related to QID 996927
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-vwfm-42q6-qj75 | org.jenkins-ci.plugins:config-file-provider |
|