Description
Jenkins TestNG Results Plugin 554.va4a552116332 and earlier renders the unescaped test descriptions and exception messages provided in test results if certain job-level options are set, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs or control test results.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-8hv7-4vfc-w8pg | Cross-site Scripting in Jenkins TestNG Results Plugin |
References
History
Wed, 20 Nov 2024 16:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-11-20T15:46:21.953Z
Reserved: 2022-06-29T00:00:00.000Z
Link: CVE-2022-34778
Updated: 2024-08-03T09:22:10.390Z
Status : Modified
Published: 2022-06-30T18:15:09.747
Modified: 2024-11-21T07:10:10.030
Link: CVE-2022-34778
No data.
OpenCVE Enrichment
No data.
Weaknesses
Github GHSA