GHSA-f82v-pg74-6686
Dashboard / Vulnerabilities / GHSA-f82v-pg74-6686
Summary: Reflected XSS vulnerability in Jenkins AWSEB Deployment Plugin
Details: AWSEB Deployment Plugin 0.3.19 and earlier does not escape various values printed as part of form validation output. This results in a reflected cross-site scripting (XSS) vulnerability. AWSEB Deployment Plugin 0.3.20 escapes the values printed as part of the affected form validation endpoints.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-2174, https://github.com/jenkinsci/awseb-deployment-plugin, https://jenkins.io/security/advisory/2020-04-07/#SECURITY-1769, http://www.openwall.com/lists/oss-security/2020/04/07/3
Affected packages
Package
Name: br.com.ingenieux.jenkins.plugins:awseb-deployment-plugin
Purl: pkg:maven/br.com.ingenieux.jenkins.plugins/awseb-deployment-plugin
Affected ranges
Type: ECOSYSTEM
Events:
