{"schema_version":"1.7.3","id":"GHSA-ph74-8rgx-64c5","published":"2023-02-15T15:30:41Z","modified":"2024-02-16T08:14:14.307474Z","aliases":["CVE-2023-25761"],"summary":"Cross-site Scripting in Jenkins JUnit Plugin","details":"Jenkins JUnit Plugin 1166.va_436e268e972 and earlier does not escape test case class names in JavaScript expressions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control test case class names in the JUnit resources processed by the plugin.","affected":[{"package":{"name":"org.jenkins-ci.plugins:junit","ecosystem":"Maven","purl":"pkg:maven/org.jenkins-ci.plugins/junit"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1166.1168.vd6b_8042a_06de"}]}],"versions":["1.0","1.1","1.10","1.11","1.12","1.13","1.14","1.15","1.18","1.19","1.2","1.2-beta-1","1.2-beta-2","1.2-beta-3","1.2-beta-4","1.20","1.21","1.22","1.22-beta-1","1.22.1","1.22.2","1.23","1.24","1.25","1.26","1.26.1","1.27","1.28","1.29","1.3","1.30","1.31","1.32","1.33","1.34","1.35","1.36","1.37","1.38","1.39","1.4","1.41","1.42","1.43","1.44","1.45","1.46","1.47","1.48","1.49","1.5","1.50","1.51","1.52","1.53","1.53.0.1","1.54","1.54.1","1.54.2","1.54.3","1.55","1.56","1.57","1.58","1.59","1.6","1.60","1.61","1.62","1.63","1.7","1.8","1.9","1119.1121.vc43d0fc45561","1119.1122.v750e65d31b_db_","1119.1124.va_a_8ccde5658f","1119.va_a_5e9068da_d7","1143.1145.v81b_b_9579a_019","1143.v8d9a_e3355270","1144.v909f4d9978e8","1150.v5c2848328b_60","1153.v1c24f1a_d2553","1156.vcf492e95a_a_b_0","1159.v0b_396e1e07dd","1160.vf1f01a_a_ea_b_7f","1166.va_436e268e972"],"database_specific":{"last_known_affected_version_range":"<= 1166.va","source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2023/02/GHSA-ph74-8rgx-64c5/GHSA-ph74-8rgx-64c5.json"}}],"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-25761"},{"type":"WEB","url":"https://github.com/jenkinsci/junit-plugin/commit/d6b8042a06de4aaaf0942ad79036095b853eea02"},{"type":"WEB","url":"https://www.jenkins.io/security/advisory/2023-02-15/#SECURITY-3032"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2023/02/15/4"}],"database_specific":{"cwe_ids":["CWE-79"],"github_reviewed":true,"github_reviewed_at":"2023-02-15T18:24:22Z","nvd_published_at":"2023-02-15T14:15:00Z","severity":"MODERATE"},"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}