GHSA-qmf3-w5jf-cv54

Suggest an improvement
Source
https://github.com/advisories/GHSA-qmf3-w5jf-cv54
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-qmf3-w5jf-cv54/GHSA-qmf3-w5jf-cv54.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-qmf3-w5jf-cv54
Aliases
Published
2022-05-24T17:19:05Z
Modified
2023-11-08T04:02:56.355077Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
XSS vulnerability in Jenkins Subversion Partial Release Manager Plugin
Details

Subversion Partial Release Manager Plugin 1.0.1 and earlier does not escape the error message for the repository URL field form validation.

This results in a reflected cross-site scripting (XSS) vulnerability that can also be exploited similar to a stored cross-site scripting vulnerability by users with Job/Configure permission.

Database specific
{
    "nvd_published_at": "2020-06-03T13:15:00Z",
    "github_reviewed_at": "2022-12-21T15:28:36Z",
    "severity": "MODERATE",
    "github_reviewed": true,
    "cwe_ids": [
        "CWE-79"
    ]
}
References

Affected packages

Maven / org.jenkins-ci.plugins:svn-partial-release-mgr

Package

Name
org.jenkins-ci.plugins:svn-partial-release-mgr
View open source insights on deps.dev
Purl
pkg:maven/org.jenkins-ci.plugins/svn-partial-release-mgr

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
1.0.1

Affected versions

1.*

1.0.1