First published: Wed Apr 12 2023(Updated: )
Jenkins Quay.io trigger Plugin 0.1 and earlier does not limit URL schemes for repository homepage URLs submitted via Quay.io trigger webhooks, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to submit crafted Quay.io trigger webhook payloads.
Credit: jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Quay.io Trigger | <=0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
Stored cross-site scripting (XSS) vulnerability exploitable by attackers submitting crafted Quay.io trigger webhook payloads.
Update Jenkins Quay.io trigger Plugin to version 0.2 or later to limit URL schemes for repository homepage URLs.
Medium severity with a CVSS score of 5.4.