QID 997305

Date Published: 2024-02-20

QID 997305: Java (Maven) Security Update for io.jenkins.plugins:warnings-ng (GHSA-wrr5-p265-7252)

A cross-site scripting vulnerability in Jenkins Warnings NG Plugin 5.0.0 and earlier allowed attacker with Job/Configure permission to inject arbitrary JavaScript in build overview pages.

Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as Medium - 5.4 severity.
  • CVSS V2 rated as Medium - 3.5 severity.
  • Solution
    Refer to Github security advisory GHSA-wrr5-p265-7252 for updates and patch information.
    Vendor References

    CVEs related to QID 997305

    Software Advisories
    Advisory ID Software Component Link
    GHSA-wrr5-p265-7252 io.jenkins.plugins:warnings-ng URL Logo github.com/advisories/GHSA-wrr5-p265-7252