Описание
Jenkins OWASP Dependency-Check Plugin has stored XSS vulnerability
Jenkins OWASP Dependency-Check Plugin 5.4.5 and earlier does not escape vulnerability metadata from Dependency-Check reports, resulting in a stored cross-site scripting (XSS) vulnerability.
Пакеты
Наименование
org.jenkins-ci.plugins:dependency-check-jenkins-plugin
maven
Затронутые версииВерсия исправления
< 5.4.6
5.4.6
Связанные уязвимости
CVSS3: 5.4
nvd
почти 2 года назад
Jenkins OWASP Dependency-Check Plugin 5.4.5 and earlier does not escape vulnerability metadata from Dependency-Check reports, resulting in a stored cross-site scripting (XSS) vulnerability.