Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-874r-46c6-7p4r

Опубликовано: 16 мар. 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Stored Cross-site Scripting vulnerability in Jenkins Favorite Plugin

Jenkins Favorite Plugin 2.4.0 and earlier does not escape the names of jobs in the favorite column, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure or Item/Create permissions.

Пакеты

Наименование

org.jvnet.hudson.plugins:favorite

maven
Затронутые версииВерсия исправления

< 2.4.1

2.4.1

EPSS

Процентиль: 93%
0.09374
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 3.5
redhat
почти 4 года назад

Jenkins Favorite Plugin 2.4.0 and earlier does not escape the names of jobs in the favorite column, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure or Item/Create permissions.

CVSS3: 5.4
nvd
почти 4 года назад

Jenkins Favorite Plugin 2.4.0 and earlier does not escape the names of jobs in the favorite column, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure or Item/Create permissions.

EPSS

Процентиль: 93%
0.09374
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79