GHSA-q397-w28f-jx97

Suggest an improvement
Source
https://github.com/advisories/GHSA-q397-w28f-jx97
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-q397-w28f-jx97/GHSA-q397-w28f-jx97.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-q397-w28f-jx97
Aliases
Published
2022-05-24T17:19:04Z
Modified
2023-11-08T04:02:56.051338Z
Severity
  • 5.4 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
Stored XSS vulnerability in Jenkins ECharts API Plugin
Details

ECharts API Plugin 4.7.0-3 and earlier does not escape the display name of the builds in the trend chart.

This results in a stored cross-site scripting (XSS) vulnerability that can be exploited by users with Run/Update permission.

ECharts API Plugin 4.7.0-4 escapes the display name.

Database specific
{
    "nvd_published_at": "2020-06-03T13:15:00Z",
    "github_reviewed_at": "2022-12-20T22:41:34Z",
    "severity": "MODERATE",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-79"
    ]
}
References

Affected packages

Maven / io.jenkins.plugins:echarts-api

Package

Name
io.jenkins.plugins:echarts-api
View open source insights on deps.dev
Purl
pkg:maven/io.jenkins.plugins/echarts-api

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.7.0-4

Affected versions

4.*

4.4.0-1-beta1
4.4.0-2-beta1
4.4.0-3-beta1
4.4.0-4-beta1
4.4.0-5-beta1
4.4.0-6-beta1
4.4.0-7-beta1
4.4.0-8-beta1
4.6.0-1-beta1
4.6.0-2-beta1
4.6.0-3-beta1
4.6.0-4-beta1
4.6.0-5-beta1
4.6.0-7
4.6.0-8
4.6.0-9
4.6.0-10
4.7.0-1
4.7.0-2
4.7.0-3