Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cfvw-84vq-43mx

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8

Описание

Stored XSS vulnerability in Jenkins Deployer Framework Plugin

Deployer Framework Plugin is a framework plugin allowing other plugins to provide a way to deploy artifacts. Deployer Framework Plugin 1.2 and earlier does not escape the URL displayed in the build home page. This results in a stored cross-site scripting (XSS) vulnerability exploitable by users able to provide the location.

The exploitability of this vulnerability depends on the specific implementation using Deployer Framework Plugin. The Jenkins security team is not aware of any exploitable implementation.

Deployer Framework Plugin 1.3 escapes the URL.

Пакеты

Наименование

org.jenkins-ci.plugins:deployer-framework

maven
Затронутые версииВерсия исправления

<= 1.2

1.3

EPSS

Процентиль: 32%
0.00121
Низкий

8 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 5 лет назад

Jenkins Deployer Framework Plugin 1.2 and earlier does not escape the URL displayed in the build home page, resulting in a stored cross-site scripting vulnerability.

EPSS

Процентиль: 32%
0.00121
Низкий

8 High

CVSS3

Дефекты

CWE-79