Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-h6qc-455m-7v6v

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8

Описание

Stored XSS vulnerability in single axis builds tooltips in Jenkins Matrix Project Plugin

Matrix Project Plugin 1.16 and earlier does not escape node names shown in tooltips on the overview page of builds with a single axis. This results in a stored cross-site scripting (XSS) vulnerability exploitable by users with Agent/Configure permission.

Matrix Project Plugin 1.17 escapes the node names shown in these tooltips.

Пакеты

Наименование

org.jenkins-ci.plugins:matrix-project

maven
Затронутые версииВерсия исправления

<= 1.16

1.17

EPSS

Процентиль: 52%
0.00289
Низкий

8 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 8
redhat
больше 5 лет назад

Jenkins Matrix Project Plugin 1.16 and earlier does not escape the node names shown in tooltips on the overview page of builds with a single axis, resulting in a stored cross-site scripting vulnerability.

CVSS3: 5.4
nvd
больше 5 лет назад

Jenkins Matrix Project Plugin 1.16 and earlier does not escape the node names shown in tooltips on the overview page of builds with a single axis, resulting in a stored cross-site scripting vulnerability.

EPSS

Процентиль: 52%
0.00289
Низкий

8 High

CVSS3

Дефекты

CWE-79