Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7577-f8fp-5977

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Stored Cross-Site Scripting Vulnerability in Jenkins Shelve Project Plugin

A cross-site scripting vulnerability exists in Jenkins Shelve Project Plugin 1.5 and earlier in ShelveProjectAction/index.jelly, ShelvedProjectsAction/index.jelly that allows attackers with Job/Configure permission to define JavaScript that would be executed in another user's browser when that other user performs some UI actions.

Пакеты

Наименование

org.jenkins-ci.plugins:shelve-project-plugin

maven
Затронутые версииВерсия исправления

<= 1.5

2.0

EPSS

Процентиль: 18%
0.00058
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 7 лет назад

A cross-site scripting vulnerability exists in Jenkins Shelve Project Plugin 1.5 and earlier in ShelveProjectAction/index.jelly, ShelvedProjectsAction/index.jelly that allows attackers with Job/Configure permission to define JavaScript that would be executed in another user's browser when that other user performs some UI actions.

EPSS

Процентиль: 18%
0.00058
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79