Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-65cq-whr4-7c2v

Опубликовано: 17 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Persistent XSS vulnerability in Jenkins OWASP Dependency-Check Plugin

The custom Details view of the Static Analysis Utilities based OWASP Dependency-Check Plugin, was vulnerable to a persisted cross-site scripting vulnerability: Malicious users able to influence the input to this plugin could insert arbitrary HTML into this view.

Пакеты

Наименование

org.jenkins-ci.plugins:dependency-check-jenkins-plugin

maven
Затронутые версииВерсия исправления

<= 2.0.1.1

2.0.1.2

EPSS

Процентиль: 17%
0.00054
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
больше 8 лет назад

The custom Details view of the Static Analysis Utilities based OWASP Dependency-Check Plugin, was vulnerable to a persisted cross-site scripting vulnerability: Malicious users able to influence the input to this plugin could insert arbitrary HTML into this view.

EPSS

Процентиль: 17%
0.00054
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79