Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-f9gf-2q87-5m44

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Stored XSS vulnerability in Jenkins Scriptler Plugin

Jenkins Scriptler Plugin 3.3 and earlier does not escape the name of scripts on the UI when asking to confirm their deletion.

This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create Scriptler scripts.

Jenkins Scriptler Plugin 3.4 escapes the name of scripts on the UI when asking to confirm their deletion.

Пакеты

Наименование

org.jenkins-ci.plugins:scriptler

maven
Затронутые версииВерсия исправления

<= 3.3

3.4

EPSS

Процентиль: 43%
0.00205
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
около 4 лет назад

Jenkins Scriptler Plugin 3.3 and earlier does not escape the name of scripts on the UI when asking to confirm their deletion, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by exploitable by attackers able to create Scriptler scripts.

EPSS

Процентиль: 43%
0.00205
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79