GHSA-vqp8-h53h-3jfh
Dashboard / Vulnerabilities / GHSA-vqp8-h53h-3jfh
Summary: Stored XSS vulnerability in Jenkins VncRecorder Plugin
Details: VncRecorder Plugin 1.25 and earlier does not escape a tool path in the `checkVncServ` form validation endpoint accessed e.g. via job configuration forms. This results in a stored cross-site scripting (XSS) vulnerability exploitable by Jenkins administrators. VncRecorder Plugin 1.35 escapes the tool path.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-2205, https://github.com/jenkinsci/vncrecorder-plugin, https://jenkins.io/security/advisory/2020-07-02/#SECURITY-1728%20(1), http://www.openwall.com/lists/oss-security/2020/07/02/7
Affected packages
Package
Name: org.jenkins-ci.plugins:vncrecorder
Purl: pkg:maven/org.jenkins-ci.plugins/vncrecorder
Affected ranges
Type: ECOSYSTEM
Events:
