GHSA-7q9r-vhg2-789w
Dashboard / Vulnerabilities / GHSA-7q9r-vhg2-789w
Summary: Stored XSS vulnerability in Jenkins brakeman Plugin
Details: brakeman Plugin 0.12 and earlier did not escape values received from parsed JSON files when rendering them, resulting in a stored cross-site scripting vulnerability. This vulnerability can be exploited by users able to control the Brakeman post-build step input data.\n\nbrakeman Plugin 0.13 escape affected values from the parsed file as they are recorded. This fix is only applied to newly recorded data after a fixed version of the plugin is installed; historical data may still contain unsafe values.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-2122, https://github.com/jenkinsci/brakeman-plugin, https://jenkins.io/security/advisory/2020-02-12/#SECURITY-1644, http://www.openwall.com/lists/oss-security/2020/02/12/3
Affected packages
Package
Name: org.jenkins-ci.plugins:brakeman
Purl: pkg:maven/org.jenkins-ci.plugins/brakeman
Affected ranges
Type: ECOSYSTEM
Events:
