Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-8h77-3xwr-hqhh

Опубликовано: 16 июн. 2021
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Cross-site scripting in Jenkins Kiuwan Plugin

Jenkins Kiuwan Plugin 1.6.0 and earlier does not escape query parameters in an error message for a form validation endpoint, resulting in a reflected cross-site scripting (XSS) vulnerability.

Only older releases of Jenkins are affected by this vulnerability. Jenkins 2.275 and newer, LTS 2.263.2 and newer include a protection preventing this from being exploitable.

Jenkins Kiuwan Plugin 1.6.1 escapes affected parts of the error message in the form validation endpoint.

Пакеты

Наименование

org.jenkins-ci.plugins:kiuwanJenkinsPlugin

maven
Затронутые версииВерсия исправления

< 1.6.1

1.6.1

EPSS

Процентиль: 38%
0.00168
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
nvd
больше 4 лет назад

Jenkins Kiuwan Plugin 1.6.0 and earlier does not escape query parameters in an error message for a form validation endpoint, resulting in a reflected cross-site scripting (XSS) vulnerability.

EPSS

Процентиль: 38%
0.00168
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79