CVE-2023-6148
CVSS 3.1 Score 5.4 of 10 (medium)
Details
Published Jan 9, 2024
Updated: Jan 24, 2024
CWE ID 79
Summary
CVE-2023-6148 is a vulnerability affecting the Qualys Jenkins Plugin for Policy Compliance before version 1.0.6. This issue arises from a missing permission check during a connectivity check to Qualys Cloud Services. Consequently, any user with login access and the ability to configure or edit jobs can potentially misuse the plugin to control responses to malicious requests. These requests could carry XSS payloads that are processed in the response data, resulting in XSS vulnerabilities.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Qualys Policy Compliance
Affected Vendors
- Qualys