Advisory Database
  • Advisories
  • Dependency Scanning
  1. maven
  2. ›
  3. org.jenkins-ci.plugins/testng-plugin
  4. ›
  5. CVE-2023-32984

CVE-2023-32984: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

May 16, 2023 (updated May 17, 2023)

Jenkins TestNG Results Plugin 730.v4c5283037693 and earlier does not escape several values that are parsed from TestNG report files and displayed on the plugin’s test information pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a crafted TestNG report file.

References

  • github.com/advisories/GHSA-h3hg-r97v-5r9w
  • nvd.nist.gov/vuln/detail/CVE-2023-32984
  • www.jenkins.io/security/advisory/2023-05-16/

Code Behaviors & Features

Detect and mitigate CVE-2023-32984 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 730.732.v959a

Fixed versions

  • 730.732.v959a

Solution

Upgrade to version 730.732.v959a or above.

Impact 5.4 MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Learn more about CVSS

Weakness

  • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Source file

maven/org.jenkins-ci.plugins/testng-plugin/CVE-2023-32984.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Wed, 14 May 2025 12:15:29 +0000.