Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-g4j6-m3m3-crw8

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8

Описание

Stored XSS vulnerability in Jenkins upstream cause

Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the upstream job's display name shown as part of a build cause, resulting in a stored cross-site scripting vulnerability.

Jenkins 2.245, LTS 2.235.2 escapes the job display name.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

<= 2.235.1

2.235.2

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 2.236, <= 2.244

2.245

EPSS

Процентиль: 66%
0.00524
Низкий

8 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 8
redhat
больше 5 лет назад

Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the upstream job's display name shown as part of a build cause, resulting in a stored cross-site scripting vulnerability.

CVSS3: 5.4
nvd
больше 5 лет назад

Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the upstream job's display name shown as part of a build cause, resulting in a stored cross-site scripting vulnerability.

CVSS3: 5.4
debian
больше 5 лет назад

Jenkins 2.244 and earlier, LTS 2.235.1 and earlier does not escape the ...

EPSS

Процентиль: 66%
0.00524
Низкий

8 High

CVSS3

Дефекты

CWE-79