QID 997359
Date Published: 2024-02-20
QID 997359: Java (Maven) Security Update for org.jenkins-ci.plugins:shelve-project-plugin (GHSA-7577-f8fp-5977)
A cross-site scripting vulnerability exists in Jenkins Shelve Project Plugin 1.5 and earlier in ShelveProjectAction/index.jelly, ShelvedProjectsAction/index.jelly that allows attackers with Job/Configure permission to define JavaScript that would be executed in another user's browser when that other user performs some UI actions.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-7577-f8fp-5977 for updates and patch information.
Vendor References
- GHSA-7577-f8fp-5977 -
github.com/advisories/GHSA-7577-f8fp-5977
CVEs related to QID 997359
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-7577-f8fp-5977 | org.jenkins-ci.plugins:shelve-project-plugin |
|