Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-6g4r-q7qg-6qx6

Опубликовано: 24 июн. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8

Описание

Cross-site Scripting vulnerability in Jenkins

Since Jenkins 2.340, the tooltip of the build button in list views supports HTML without escaping the job display name.

This vulnerability is known to be exploitable by attackers with Job/Configure permission.

Jenkins 2.356 addresses this vulnerability. The tooltip of the build button in list views is now escaped.

No Jenkins LTS release is affected by SECURITY-2776 or SECURITY-2780, as these were not present in Jenkins 2.332.x and fixed in the 2.346.x line before 2.346.1.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 2.340, < 2.356

2.356

EPSS

Процентиль: 94%
0.11821
Средний

8 High

CVSS3

Дефекты

CWE-22
CWE-79

Связанные уязвимости

CVSS3: 6.1
redhat
больше 3 лет назад

In Jenkins 2.340 through 2.355 (both inclusive) the tooltip of the build button in list views supports HTML without escaping the job display name, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

CVSS3: 5.4
nvd
больше 3 лет назад

In Jenkins 2.340 through 2.355 (both inclusive) the tooltip of the build button in list views supports HTML without escaping the job display name, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

CVSS3: 5.4
debian
больше 3 лет назад

In Jenkins 2.340 through 2.355 (both inclusive) the tooltip of the bui ...

EPSS

Процентиль: 94%
0.11821
Средний

8 High

CVSS3

Дефекты

CWE-22
CWE-79