Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5mwr-jg3r-jv66

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS4: 2.1

Описание

Jenkins allows Cross-Site Scripting (XSS)

Cross-site scripting (XSS) vulnerability in the slave overview page in Jenkins before 1.638 and LTS before 1.625.2 allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the slave offline status message.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

< 1.625.2

1.625.2

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 1.626, < 1.638

1.638

EPSS

Процентиль: 37%
0.0016
Низкий

2.1 Low

CVSS4

Дефекты

CWE-79

Связанные уязвимости

ubuntu
около 10 лет назад

Cross-site scripting (XSS) vulnerability in the slave overview page in Jenkins before 1.638 and LTS before 1.625.2 allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the slave offline status message.

redhat
около 10 лет назад

Cross-site scripting (XSS) vulnerability in the slave overview page in Jenkins before 1.638 and LTS before 1.625.2 allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the slave offline status message.

nvd
около 10 лет назад

Cross-site scripting (XSS) vulnerability in the slave overview page in Jenkins before 1.638 and LTS before 1.625.2 allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the slave offline status message.

debian
около 10 лет назад

Cross-site scripting (XSS) vulnerability in the slave overview page in ...

EPSS

Процентиль: 37%
0.0016
Низкий

2.1 Low

CVSS4

Дефекты

CWE-79