Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jf8x-943c-r4h6

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Jenkins Pipeline Aggregator View Plugin stored XSS vulnerability

Jenkins Pipeline Aggregator View Plugin 1.8 and earlier does not escape information shown on its view, resulting in a stored XSS vulnerability exploitable by attackers able to affects view content such as job display name or pipeline stage names.

Пакеты

Наименование

com.paul8620.jenkins.plugins:pipeline-aggregator-view

maven
Затронутые версииВерсия исправления

< 1.9

1.9

EPSS

Процентиль: 46%
0.00233
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
около 6 лет назад

Jenkins Pipeline Aggregator View Plugin 1.8 and earlier does not escape information shown on its view, resulting in a stored XSS vulnerability exploitable by attackers able to affects view content such as job display name or pipeline stage names.

EPSS

Процентиль: 46%
0.00233
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79