Cross-site Scripting in Jenkins JUnit Plugin
Moderate severity
GitHub Reviewed
Published
Feb 15, 2023
to the GitHub Advisory Database
•
Updated Jan 5, 2024
Package
Affected versions
<= 1166.va
Patched versions
1166.1168.vd6b_8042a_06de
Description
Published by the National Vulnerability Database
Feb 15, 2023
Published to the GitHub Advisory Database
Feb 15, 2023
Reviewed
Feb 15, 2023
Last updated
Jan 5, 2024
Jenkins JUnit Plugin 1166.va_436e268e972 and earlier does not escape test case class names in JavaScript expressions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control test case class names in the JUnit resources processed by the plugin.
References