{"id":"GHSA-q9g4-9fx4-v533","summary":"Stored XSS vulnerability in Jenkins DotCi Plugin","details":"DotCi Plugin 2.40.00 and earlier does not escape the GitHub user name parameter provided to commit notifications when displaying them in a build cause.\n\nThis results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to submit crafted commit notifications to the `/githook/` endpoint (see also [SECURITY-2867](https://www.jenkins.io/security/advisory/2022-09-21/#SECURITY-2867)).\n\nThis vulnerability is only exploitable in Jenkins 2.314 and earlier, LTS 2.303.1 and earlier. See the [LTS upgrade guide](https://www.jenkins.io/doc/upgrade-guide/2.303/#SECURITY-2452).","aliases":["CVE-2022-41239"],"modified":"2024-02-17T05:31:39.508753Z","published":"2022-09-22T00:00:28Z","database_specific":{"cwe_ids":["CWE-79"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2022-12-06T22:40:16Z","nvd_published_at":"2022-09-21T16:15:00Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2022-41239"},{"type":"PACKAGE","url":"https://github.com/jenkinsci/DotCi"},{"type":"WEB","url":"https://plugins.jenkins.io/DotCi"},{"type":"WEB","url":"https://www.jenkins.io/security/advisory/2022-09-21/#SECURITY-2884"},{"type":"WEB","url":"https://www.jenkins.io/security/plugins/#suspensions"}],"affected":[{"package":{"name":"com.groupon.jenkins-ci.plugins:DotCi","ecosystem":"Maven","purl":"pkg:maven/com.groupon.jenkins-ci.plugins/DotCi"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"2.40.00"}]}],"versions":["1.0.0","1.0.1","1.0.2","1.0.3","1.1.0","1.1.1","1.2.0","1.2.1","1.2.2","1.3.0","1.3.1","1.3.2","1.3.3","1.3.4","2.0.0","2.1.0","2.10.0","2.11.0","2.11.1","2.11.2","2.12.0","2.12.1","2.12.2","2.12.3","2.13.0","2.13.1","2.14.0","2.14.1","2.14.2","2.14.3","2.14.4","2.14.5","2.15.0","2.15.1","2.16.0","2.16.1","2.17.0","2.18.0","2.19.0","2.19.1","2.19.3","2.19.5","2.2","2.20.0","2.20.1","2.21.0","2.22.0","2.22.1","2.23.0","2.24.0","2.24.1","2.24.2","2.24.3","2.25.0","2.25.1","2.26.0","2.27.0","2.28.0","2.28.1","2.3","2.30.2","2.30.4","2.30.7","2.31.0","2.32.0","2.32.1","2.33.0","2.34.0","2.35.0","2.36.0","2.36.1","2.36.2","2.37.0","2.38.0","2.38.1","2.38.10","2.38.11","2.38.2","2.38.3","2.38.4","2.38.5","2.38.6","2.38.7","2.38.8","2.38.9","2.39.0","2.39.1","2.39.2","2.39.3","2.39.4","2.39.5","2.39.6","2.39.7","2.39.8","2.39.9","2.4","2.40.00","2.5","2.5.1","2.5.2","2.5.3","2.5.4","2.6.0","2.6.1","2.6.2","2.6.3","2.6.4","2.6.5","2.6.6","2.6.7","2.6.8","2.6.9","2.7.0","2.7.1","2.7.2","2.7.3","2.7.4","2.7.5","2.7.6","2.7.7","2.7.8","2.8.0","2.8.1","2.8.2","2.8.3","2.8.4","2.8.5","2.8.6","2.8.7","2.8.8","2.8.9","2.9.0","2.9.1","2.9.2"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2022/09/GHSA-q9g4-9fx4-v533/GHSA-q9g4-9fx4-v533.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H"}]}