GHSA-7qpm-vmwv-hq7h

Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-7qpm-vmwv-hq7h/GHSA-7qpm-vmwv-hq7h.json
Aliases
  • CVE-2022-41240
Published
2022-09-22T00:00:28Z
Modified
2023-03-18T05:54:27.106562Z
Details

Jenkins Walti Plugin 1.0.1 and earlier does not escape the information provided by the Walti API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide malicious API responses from Walti.

References

Affected packages

Maven / org.jenkins-ci.plugins:walti

org.jenkins-ci.plugins:walti

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0

Affected versions

1.*

1.0.0
1.0.1

Database specific

{
    "last_known_affected_version_range": "<= 1.0.1"
}