Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-j927-269r-96xw

Опубликовано: 02 апр. 2023
Источник: github
Github: Прошло ревью
CVSS3: 8

Описание

Jenkins Cppcheck Plugin vulnerable to stored cross-site scripting (XSS)

Jenkins Cppcheck Plugin 1.26 and earlier does not escape file names from Cppcheck report files before showing them on the Jenkins UI.

This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control report file contents.

Пакеты

Наименование

org.jenkins-ci.plugins:cppcheck

maven
Затронутые версииВерсия исправления

<= 1.26

Отсутствует

EPSS

Процентиль: 87%
0.03203
Низкий

8 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
почти 3 года назад

Jenkins Cppcheck Plugin 1.26 and earlier does not escape file names from Cppcheck report files before showing them on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control report file contents.

EPSS

Процентиль: 87%
0.03203
Низкий

8 High

CVSS3

Дефекты

CWE-79