GHSA-wc2g-9j98-vcgw
Dashboard / Vulnerabilities / GHSA-wc2g-9j98-vcgw
Summary: Jenkins Subversion Release Manager Plugin vulnerable to cross-site scripting (XSS)
Details: Subversion Release Manager Plugin 1.2 and earlier does not escape the error message for the Repository URL field form validation. This results in a reflected cross-site scripting vulnerability that can also be exploited similar to a stored cross-site scripting vulnerability by users with Job/Configure permission.
References: https://nvd.nist.gov/vuln/detail/CVE-2020-2152, https://github.com/jenkinsci/svn-release-mgr-plugin, https://jenkins.io/security/advisory/2020-03-09/#SECURITY-1727, http://www.openwall.com/lists/oss-security/2020/03/09/1
Affected packages
Package
Name: org.jvnet.hudson.plugins:svn-release-mgr
Purl: pkg:maven/org.jvnet.hudson.plugins/svn-release-mgr
Affected ranges
Type: ECOSYSTEM
Events:
