GHSA-jcmg-9rw5-9rm2
Dashboard / Vulnerabilities / GHSA-jcmg-9rw5-9rm2
Summary: Stored XSS vulnerability in Jenkins Git Changelog Plugin
Details: A cross-site scripting vulnerability exists in Jenkins Git Changelog Plugin 2.6 and earlier in GitChangelogSummaryDecorator/summary.jelly, GitChangelogLeftsideBuildDecorator/badge.jelly, GitLogJiraFilterPostPublisher/config.jelly, GitLogBasicChangelogPostPublisher/config.jelly that allows attackers able to control the Git history parsed by the plugin to have Jenkins render arbitrary HTML on some pages.
References: https://nvd.nist.gov/vuln/detail/CVE-2018-1000426, https://jenkins.io/security/advisory/2018-09-25/#SECURITY-1122, http://www.securityfocus.com/bid/106532
Affected packages
Package
Name: de.wellnerbou.jenkins:git-changelog
Purl: pkg:maven/de.wellnerbou.jenkins/git-changelog
Affected ranges
Type: ECOSYSTEM
Events:
