Loading HuntDB...

GHSA-hvcr-927w-qcvq

GitHub Security Advisory

Stored XSS vulnerability in Jenkins Contrast Continuous Application Security Plugin

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Contrast Continuous Application Security Plugin 3.9 and earlier does not escape data returned from the Contrast service when generating a report.

This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control or modify Contrast service API responses.

Contrast Continuous Application Security Plugin 3.10 escapes the affected data.

Affected Packages

Maven org.jenkins-ci.plugins:contrast-continuous-application-security
Affected versions: 0 (fixed in 3.10)

Related CVEs

Key Information

GHSA ID
GHSA-hvcr-927w-qcvq
Published
October 19, 2022 7:00 PM
Last Modified
December 16, 2022 7:46 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
org.jenkins-ci.plugins:contrast-continuous-application-security
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 27, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.