org.jvnet.hudson.plugins.findbugs:parent@1.0-h-4 vulnerabilities

  • latest version

    1.0-h-6

  • first published

    11 years ago

  • latest version published

    9 years ago

  • licenses detected

  • package manager

  • Direct Vulnerabilities

    Known vulnerabilities in the org.jvnet.hudson.plugins.findbugs:parent package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • H
    Cross-site Scripting (XSS)

    org.jvnet.hudson.plugins.findbugs:parent is a parent pom to build findbugs plugg-in that is composed of plug-in and shaded findbugs library.

    Affected versions of this package are vulnerable to Cross-site Scripting (XSS). FindBugs Plugin 5.0.0 and earlier does not escape the annotation message in tooltips. This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide report files to FindBugs Plugin’s post build step.

    How to fix Cross-site Scripting (XSS)?

    There is no fixed version for org.jvnet.hudson.plugins.findbugs:parent.

    [0,)
    • H
    XML External Entity (XXE) Injection

    org.jvnet.hudson.plugins.findbugs:parent is a Jenkins findbugs plugin.

    Affected version of this package are vulnerable to XML External Entity (XXE) Injection in files it parses as part of the build process. It allows attackers with user permissions in Jenkins to extract secrets from the Jenkins master, perform server-side request forgery, or denial-of-service attacks.

    [,4.72)