QID 997500
Date Published: 2024-02-26
QID 997500: Java (Maven) Security Update for org.jenkins-ci.plugins:dependency-check-jenkins-plugin (GHSA-65cq-whr4-7c2v)
The custom Details view of the Static Analysis Utilities based OWASP Dependency-Check Plugin, was vulnerable to a persisted cross-site scripting vulnerability: Malicious users able to influence the input to this plugin could insert arbitrary HTML into this view.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-65cq-whr4-7c2v for updates and patch information.
Vendor References
- GHSA-65cq-whr4-7c2v -
github.com/advisories/GHSA-65cq-whr4-7c2v
CVEs related to QID 997500
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-65cq-whr4-7c2v | org.jenkins-ci.plugins:dependency-check-jenkins-plugin |
|