Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9jcv-v4jp-w3cq

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Cross-site Scripting in Jenkins Core

A cross-site scripting vulnerability exists in Jenkins 2.115 and older, LTS 2.107.1 and older, in confirmationList.jelly and stopButton.jelly that allows attackers with Job/Configure and/or Job/Create permission to create an item name containing JavaScript that would be executed in another user's browser when that other user performs some UI actions.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 2.108, <= 2.115

2.116

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

<= 2.107.1

2.107.2

EPSS

Процентиль: 44%
0.00215
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
redhat
почти 8 лет назад

A cross-site scripting vulnerability exists in Jenkins 2.115 and older, LTS 2.107.1 and older, in confirmationList.jelly and stopButton.jelly that allows attackers with Job/Configure and/or Job/Create permission to create an item name containing JavaScript that would be executed in another user's browser when that other user performs some UI actions.

CVSS3: 5.4
nvd
почти 8 лет назад

A cross-site scripting vulnerability exists in Jenkins 2.115 and older, LTS 2.107.1 and older, in confirmationList.jelly and stopButton.jelly that allows attackers with Job/Configure and/or Job/Create permission to create an item name containing JavaScript that would be executed in another user's browser when that other user performs some UI actions.

CVSS3: 5.4
debian
почти 8 лет назад

A cross-site scripting vulnerability exists in Jenkins 2.115 and older ...

EPSS

Процентиль: 44%
0.00215
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79