Описание
Jenkins buildgraph-view Plugin does not escape the build URL
Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the build URL.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs or views.
As of publication of this advisory, there is no fix.
Пакеты
Наименование
org.jenkins-ci.plugins:buildgraph-view
maven
Затронутые версииВерсия исправления
<= 1.8
Отсутствует
Связанные уязвимости
CVSS3: 5.5
nvd
3 месяца назад
Jenkins buildgraph-view Plugin 1.8 and earlier does not escape the build URL, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs or views.