Описание
Jenkins Associated Files Plugin vulnerable to cross-site scripting (XSS)
Jenkins Associated Files Plugin 0.2.1 and earlier does not escape names of associated files, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. Currently, there are no known workarounds or patches.
Пакеты
Наименование
org.jenkins-ci.main:associated-files-plugin
maven
Затронутые версииВерсия исправления
<= 0.2.1
Отсутствует
Связанные уязвимости
CVSS3: 5.4
nvd
около 3 лет назад
Jenkins Associated Files Plugin 0.2.1 and earlier does not escape names of associated files, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.