Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7cjc-xppr-xj6x

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Improper Neutralization of Input During Web Page Generation in Jenkins

Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not escape the SCM tag name on the tooltip for SCM tag actions, resulting in a stored XSS vulnerability exploitable by users able to control SCM tag names for these actions.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

<= 2.176.3

2.176.4

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 2.177, <= 2.196

2.197

EPSS

Процентиль: 63%
0.00454
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
redhat
больше 6 лет назад

Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not escape the SCM tag name on the tooltip for SCM tag actions, resulting in a stored XSS vulnerability exploitable by users able to control SCM tag names for these actions.

CVSS3: 5.4
nvd
больше 6 лет назад

Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not escape the SCM tag name on the tooltip for SCM tag actions, resulting in a stored XSS vulnerability exploitable by users able to control SCM tag names for these actions.

CVSS3: 5.4
debian
больше 6 лет назад

Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not escape the ...

EPSS

Процентиль: 63%
0.00454
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79