GHSA-q9g4-9fx4-v533

Suggest an improvement
Source
https://github.com/advisories/GHSA-q9g4-9fx4-v533
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-q9g4-9fx4-v533/GHSA-q9g4-9fx4-v533.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-q9g4-9fx4-v533
Aliases
Published
2022-09-22T00:00:28Z
Modified
2024-02-17T05:19:07.198288Z
Severity
  • 8.8 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Stored XSS vulnerability in Jenkins DotCi Plugin
Details

DotCi Plugin 2.40.00 and earlier does not escape the GitHub user name parameter provided to commit notifications when displaying them in a build cause.

This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to submit crafted commit notifications to the /githook/ endpoint (see also SECURITY-2867).

This vulnerability is only exploitable in Jenkins 2.314 and earlier, LTS 2.303.1 and earlier. See the LTS upgrade guide.

Database specific
{
    "nvd_published_at": "2022-09-21T16:15:00Z",
    "cwe_ids": [
        "CWE-79"
    ],
    "severity": "HIGH",
    "github_reviewed": true,
    "github_reviewed_at": "2022-12-06T22:40:16Z"
}
References

Affected packages

Maven / com.groupon.jenkins-ci.plugins:DotCi

Package

Name
com.groupon.jenkins-ci.plugins:DotCi
View open source insights on deps.dev
Purl
pkg:maven/com.groupon.jenkins-ci.plugins/DotCi

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
2.40.00

Affected versions

1.*

1.0.0
1.0.1
1.0.2
1.0.3
1.1.0
1.1.1
1.2.0
1.2.1
1.2.2
1.3.0
1.3.1
1.3.2
1.3.3
1.3.4

2.*

2.0.0
2.1.0
2.2
2.3
2.4
2.5
2.5.1
2.5.2
2.5.3
2.5.4
2.6.0
2.6.1
2.6.2
2.6.3
2.6.4
2.6.5
2.6.6
2.6.7
2.6.8
2.6.9
2.7.0
2.7.1
2.7.2
2.7.3
2.7.4
2.7.5
2.7.6
2.7.7
2.7.8
2.8.0
2.8.1
2.8.2
2.8.3
2.8.4
2.8.5
2.8.6
2.8.7
2.8.8
2.8.9
2.9.0
2.9.1
2.9.2
2.10.0
2.11.0
2.11.1
2.11.2
2.12.0
2.12.1
2.12.2
2.12.3
2.13.0
2.13.1
2.14.0
2.14.1
2.14.2
2.14.3
2.14.4
2.14.5
2.15.0
2.15.1
2.16.0
2.16.1
2.17.0
2.18.0
2.19.0
2.19.1
2.19.3
2.19.5
2.20.0
2.20.1
2.21.0
2.22.0
2.22.1
2.23.0
2.24.0
2.24.1
2.24.2
2.24.3
2.25.0
2.25.1
2.26.0
2.27.0
2.28.0
2.28.1
2.30.2
2.30.4
2.30.7
2.31.0
2.32.0
2.32.1
2.33.0
2.34.0
2.35.0
2.36.0
2.36.1
2.36.2
2.37.0
2.38.0
2.38.1
2.38.2
2.38.3
2.38.4
2.38.5
2.38.6
2.38.7
2.38.8
2.38.9
2.38.10
2.38.11
2.39.0
2.39.1
2.39.2
2.39.3
2.39.4
2.39.5
2.39.6
2.39.7
2.39.8
2.39.9
2.40.00