CRITICAL 9.0
GHSA-w22p-4x9f-486v
Jenkins GitHub Plugin has an XSS vulnerability
빠른 조치
GHSA-w22p-4x9f-486v — com.coravy.hudson.plugins.github:github: 아래 명령으로 수정 버전으로 올리세요.
# pom.xml: bump <version>1.46.0.1</version> for com.coravy.hudson.plugins.github:github 상세
In Jenkins GitHub Plugin versions 1.46.0 and earlier, the JavaScript that validates the "GitHub hook trigger for GITScm polling" feature improperly processes the current job URL.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by non-anonymous attackers with Overall/Read permission.
GitHub Plugin 1.46.0.1 no longer processes the current job URL as part of JavaScript implementing validation of the feature "GitHub hook trigger for GITScm polling".
이 버전이 영향받나요?
사용 중인 패키지 버전을 입력하면 즉시 평가합니다.
영향 패키지
Maven / com.coravy.hudson.plugins.github:github
최초 영향 버전:
0 수정 버전: 1.46.0.1 수정
# pom.xml: bump <version>1.46.0.1</version> for com.coravy.hudson.plugins.github:github