"value":"\nQualys Jenkins Plugin for Policy Compliance prior to version and including 1.0.5 was identified to be affected by a security flaw, which was missing a permission check while performing a connectivity check to Qualys Cloud Services. This allowed any user with login access and access to configure or edit jobs to utilize the plugin to configure a potential rouge endpoint via which\u00a0it was possible to control response for certain request which could be injected with XSS payloads leading to XSS\u00a0while processing the response data\n\n"
}
]
},
"problemtype":{
"problemtype_data":[
{
"description":[
{
"lang":"eng",
"value":"CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')",
"value":"\n\n<span style=\"background-color: rgb(255, 255, 255);\">Customers should upgrade to a minimum version of 1.0.6.</span><span style=\"background-color: rgb(255, 255, 255);\"> </span>\n\n<br>"
}
],
"value":"\nCustomers should upgrade to a minimum version of 1.0.6.\u00a0\n\n\n"