GHSA-f799-hfg3-48jp
Dashboard / Vulnerabilities / GHSA-f799-hfg3-48jp
Summary: Stored XSS vulnerability in Jenkins Sonargraph Integration Plugin
Details: Sonargraph Integration Plugin 3.0.0 and earlier does not escape the file path for the Log file field form validation. This results in a stored cross-site scripting (XSS) vulnerability that can be exploited by users with Job/Configure permission. Sonargraph Integration Plugin 3.0.1 escapes the affected part of the error message.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-2201, https://github.com/jenkinsci/sonargraph-integration-plugin, https://jenkins.io/security/advisory/2020-07-02/#SECURITY-1775, http://www.openwall.com/lists/oss-security/2020/07/02/7
Affected packages
Package
Name: org.jenkins-ci.plugins:sonargraph-integration
Purl: pkg:maven/org.jenkins-ci.plugins/sonargraph-integration
Affected ranges
Type: ECOSYSTEM
Events:
