QID 997287
Date Published: 2024-02-20
QID 997287: Java (Maven) Security Update for org.jenkins-ci.plugins:netsparker-cloud-scan (GHSA-qc3m-6xmq-7hrj)
A cross-site request forgery vulnerability in Jenkins Netsparker Cloud Scan Plugin 1.1.5 and older in the NCScanBuilder.DescriptorImpl#doValidateAPI form validation method allowed attackers to initiate a connection to an attacker-specified server.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-qc3m-6xmq-7hrj for updates and patch information.
Vendor References
- GHSA-qc3m-6xmq-7hrj -
github.com/advisories/GHSA-qc3m-6xmq-7hrj
CVEs related to QID 997287
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-qc3m-6xmq-7hrj | org.jenkins-ci.plugins:netsparker-cloud-scan |
|