Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9hg7-xmf8-jxf9

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Stored XSS vulnerability in Jenkins Liquibase Runner Plugin

Liquibase Runner Plugin 1.4.5 and earlier does not escape changeset contents when showing them on the build page.

This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide Liquibase changesets evaluated by the plugin.

Liquibase Runner Plugin 1.4.7 no longer supports evaluating changesets.

Пакеты

Наименование

org.jenkins-ci.plugins:liquibase-runner

maven
Затронутые версииВерсия исправления

<= 1.4.5

1.4.6

EPSS

Процентиль: 46%
0.00233
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 5 лет назад

Jenkins Liquibase Runner Plugin 1.4.5 and earlier does not escape changeset contents, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users able to control changeset files evaluated by the plugin.

EPSS

Процентиль: 46%
0.00233
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79