JUnit Plugin 1119.vaa5e9068da_d7 and earlier does not escape descriptions of test results.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Run/Update permission.
JUnit Plugin 1119.1121.vc43d0fc45561 applies the configured markup formatter to descriptions of test results.
{ "nvd_published_at": "2022-06-23T17:15:00Z", "github_reviewed_at": "2022-07-05T22:56:33Z", "severity": "HIGH", "github_reviewed": true, "cwe_ids": [ "CWE-79" ] }