Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hw55-f8wc-82m6

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.8

Описание

Improper Neutralization of Input During Web Page Generation in Jenkins

Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not restrict or filter values set as Jenkins URL in the global configuration, resulting in a stored XSS vulnerability exploitable by attackers with Overall/Administer permission.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

<= 2.176.3

2.176.4

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 2.177, <= 2.196

2.197

EPSS

Процентиль: 64%
0.00466
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
redhat
больше 6 лет назад

Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not restrict or filter values set as Jenkins URL in the global configuration, resulting in a stored XSS vulnerability exploitable by attackers with Overall/Administer permission.

CVSS3: 4.8
nvd
больше 6 лет назад

Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not restrict or filter values set as Jenkins URL in the global configuration, resulting in a stored XSS vulnerability exploitable by attackers with Overall/Administer permission.

CVSS3: 4.8
debian
больше 6 лет назад

Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not restrict or ...

EPSS

Процентиль: 64%
0.00466
Низкий

4.8 Medium

CVSS3

Дефекты

CWE-79