{"id":"GHSA-jf8x-943c-r4h6","summary":"Jenkins Pipeline Aggregator View Plugin stored XSS vulnerability","details":"Jenkins Pipeline Aggregator View Plugin 1.8 and earlier does not escape information shown on its view, resulting in a stored XSS vulnerability exploitable by attackers able to affects view content such as job display name or pipeline stage names.","aliases":["CVE-2019-16564"],"modified":"2024-02-16T08:07:42.293181Z","published":"2022-05-24T17:03:48Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2023-11-03T19:19:51Z","nvd_published_at":"2019-12-17T15:15:00Z","cwe_ids":["CWE-79"],"severity":"MODERATE"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2019-16564"},{"type":"WEB","url":"https://github.com/jenkinsci/pipeline-aggregator-view-plugin/commit/acb0eeeae60ec0ac2dc5c8b5639d77589aa95af3"},{"type":"WEB","url":"https://jenkins.io/security/advisory/2019-12-17/#SECURITY-1593"},{"type":"WEB","url":"http://www.openwall.com/lists/oss-security/2019/12/17/1"}],"affected":[{"package":{"name":"com.paul8620.jenkins.plugins:pipeline-aggregator-view","ecosystem":"Maven","purl":"pkg:maven/com.paul8620.jenkins.plugins/pipeline-aggregator-view"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.9"}]}],"versions":["1.0","1.1","1.2","1.3","1.4","1.4.1","1.5","1.6","1.7","1.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/05/GHSA-jf8x-943c-r4h6/GHSA-jf8x-943c-r4h6.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N"}]}