CVE-2023-35145
14.06.2023, 13:15
Jenkins Sonargraph Integration Plugin 5.0.1 and earlier does not escape the file path and the project name for the Log file field form validation, resulting in a stored cross-site scripting vulnerability exploitable by attackers with Item/Configure permission.
Vendor | Product | Version |
---|---|---|
jenkins | sonargraph_integration | 𝑥 ≤ 5.0.1 |
𝑥
= Vulnerable software versions