CVE-2017-1000109: XSS
The custom Details view of the Static Analysis Utilities based OWASP Dependency-Check Plugin, was vulnerable to a persisted cross-site scripting vulnerability: Malicious users able to influence the input to this plugin could insert arbitrary HTML into this view.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-1000109?
CVE-2017-1000109 is classified as a medium severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2017-1000109?
To fix CVE-2017-1000109, upgrade the OWASP Dependency-Check Plugin to version 2.0.1.2 or later.
What types of attacks can CVE-2017-1000109 be exploited for?
CVE-2017-1000109 can be exploited for cross-site scripting attacks, allowing attackers to inject arbitrary HTML.
Which applications are affected by CVE-2017-1000109?
CVE-2017-1000109 affects several versions of the Jenkins OWASP Dependency-Check Plugin, specifically versions 1.0.1 through 2.0.1.1.
Is user input related to CVE-2017-1000109 vulnerable?
Yes, user input that can influence the Details view of the Jenkins OWASP Dependency-Check Plugin is vulnerable to exploitation.