CVE-2019-1003023

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in maven/io.jenkins.plugins/warnings-ng

Identifiers

GHSA-cqp7-hwm3-cfg7, CVE-2019-1003023

Package Slug

maven/io.jenkins.plugins/warnings-ng

Vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Description

A cross-site scripting vulnerability exists in Jenkins Warnings Next Generation Plugin 1.0.1 and earlier in src/main/java/io/jenkins/plugins/analysis/core/model/DetailsTableModel.java, src/main/java/io/jenkins/plugins/analysis/core/model/SourceDetail.java, src/main/java/io/jenkins/plugins/analysis/core/model/SourcePrinter.java, src/main/java/io/jenkins/plugins/analysis/core/util/Sanitizer.java, src/main/java/io/jenkins/plugins/analysis/warnings/DuplicateCodeScanner.java that allows attackers with the ability to control warnings parser input to have Jenkins render arbitrary HTML.

Affected Versions

All versions up to 1.0.1

Solution

Upgrade to version 2.0.0 or above.

Last Modified

2024-01-31

source