Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hvcr-927w-qcvq

Опубликовано: 19 окт. 2022
Источник: github
Github: Прошло ревью
CVSS3: 7.5

Описание

Stored XSS vulnerability in Jenkins Contrast Continuous Application Security Plugin

Contrast Continuous Application Security Plugin 3.9 and earlier does not escape data returned from the Contrast service when generating a report.

This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control or modify Contrast service API responses.

Contrast Continuous Application Security Plugin 3.10 escapes the affected data.

Пакеты

Наименование

org.jenkins-ci.plugins:contrast-continuous-application-security

maven
Затронутые версииВерсия исправления

<= 3.9

3.10

EPSS

Процентиль: 93%
0.10502
Средний

7.5 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 3 лет назад

Jenkins Contrast Continuous Application Security Plugin 3.9 and earlier does not escape data returned from the Contrast service when generating a report, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control or modify Contrast service API responses.

EPSS

Процентиль: 93%
0.10502
Средний

7.5 High

CVSS3

Дефекты

CWE-79