QID 996991
Date Published: 2024-01-31
QID 996991: Java (Maven) Security Update for jenkins:repository (GHSA-9pvw-8q92-hm9w)
Jenkins Maven Repository Server Plugin 1.10 and earlier does not escape the versions of build artifacts on the Build Artifacts As Maven Repository page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control maven project versions in pom.xml.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-9pvw-8q92-hm9w for updates and patch information.
Vendor References
- GHSA-9pvw-8q92-hm9w -
github.com/advisories/GHSA-9pvw-8q92-hm9w
CVEs related to QID 996991
Software Advisories
| Advisory ID | Software | Component | Link |
|---|