Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hvmc-7g2x-r3p9

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8

Описание

Jenkins Cross-Site Scripting vulnerability in help icons

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons. Tooltip values can be contributed by plugins, some of which use user-specified values. This results in a stored cross-site scripting (XSS) vulnerability. Jenkins 2.252, LTS 2.235.4 escapes the tooltip content of help icons.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

<= 2.235.3

2.235.4

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 2.236, <= 2.251

2.252

EPSS

Процентиль: 85%
0.02572
Низкий

8 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
redhat
больше 5 лет назад

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability.

CVSS3: 5.4
nvd
больше 5 лет назад

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability.

CVSS3: 5.4
debian
больше 5 лет назад

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the ...

EPSS

Процентиль: 85%
0.02572
Низкий

8 High

CVSS3

Дефекты

CWE-79