Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hvmc-7g2x-r3p9

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8

Описание

Jenkins Cross-Site Scripting vulnerability in help icons

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons. Tooltip values can be contributed by plugins, some of which use user-specified values. This results in a stored cross-site scripting (XSS) vulnerability. Jenkins 2.252, LTS 2.235.4 escapes the tooltip content of help icons.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

<= 2.235.3

2.235.4

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 2.236, <= 2.251

2.252

EPSS

Процентиль: 93%
0.06765
Низкий

8 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
redhat
около 6 лет назад

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability.

CVSS3: 5.4
nvd
около 6 лет назад

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons, resulting in a stored cross-site scripting (XSS) vulnerability.

CVSS3: 5.4
debian
около 6 лет назад

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the ...

EPSS

Процентиль: 93%
0.06765
Низкий

8 High

CVSS3

Дефекты

CWE-79