JUnit Plugin 1119.vaa5e9068da_d7 and earlier does not escape descriptions of test results.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Run/Update permission.
JUnit Plugin 1119.1121.vc43d0fc45561 applies the configured markup formatter to descriptions of test results.
{
"severity": "HIGH",
"github_reviewed": true,
"cwe_ids": [
"CWE-79"
],
"github_reviewed_at": "2022-07-05T22:56:33Z",
"nvd_published_at": "2022-06-23T17:15:00Z"
}