Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-298r-5c48-7q2r

Опубликовано: 16 нояб. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8

Описание

Jenkins JUnit Plugin subject to Cross-site Scripting via URL conversion

JUnit Plugin 1159.v0b_396e1e07dd and earlier converts HTTP(S) URLs in test report output to clickable links.

This is done in an unsafe manner, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

JUnit Plugin 1160.vf1f01a_a_ea_b_7f no longer converts URLs to clickable links.

Пакеты

Наименование

org.jenkins-ci.plugins:junit

maven
Затронутые версииВерсия исправления

<= 1159.v0b

1160.vf1f01a_a_ea_b_7f

EPSS

Процентиль: 67%
0.00548
Низкий

8 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 8
redhat
почти 3 года назад

Jenkins JUnit Plugin 1159.v0b_396e1e07dd and earlier converts HTTP(S) URLs in test report output to clickable links in an unsafe manner, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

CVSS3: 5.4
nvd
почти 3 года назад

Jenkins JUnit Plugin 1159.v0b_396e1e07dd and earlier converts HTTP(S) URLs in test report output to clickable links in an unsafe manner, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

EPSS

Процентиль: 67%
0.00548
Низкий

8 High

CVSS3

Дефекты

CWE-79