QID 996948
Date Published: 2024-01-29
QID 996948: Java (Maven) Security Update for org.6wind.jenkins:lockable-resources (GHSA-wqjj-c9cx-q7cf)
A cross site scripting vulnerability in Jenkins Lockable Resources Plugin 2.4 and earlier allows attackers able to control resource names to inject arbitrary JavaScript in web pages rendered by the plugin.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-wqjj-c9cx-q7cf for updates and patch information.
Vendor References
- GHSA-wqjj-c9cx-q7cf -
github.com/advisories/GHSA-wqjj-c9cx-q7cf
CVEs related to QID 996948
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-wqjj-c9cx-q7cf | org.6wind.jenkins:lockable-resources |
|