Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-jwhm-9cjm-4493

Опубликовано: 16 июн. 2021
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Cross-site Scripting in Jenkins Dashboard View Plugin

Jenkins Dashboard View Plugin prior to 2.16 and 2.12.1 does not escape URLs referenced in Image Dashboard Portlets, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Configure permission.

As part of this fix, the property for image URLs was changed from url to imageUrl. Existing Configuration as Code configurations are still supported, but exports will emit the new property.

Пакеты

Наименование

org.jenkins-ci.plugins:dashboard-view

maven
Затронутые версииВерсия исправления

>= 2.13, < 2.16

2.16

Наименование

org.jenkins-ci.plugins:dashboard-view

maven
Затронутые версииВерсия исправления

< 2.12.1

2.12.1

EPSS

Процентиль: 41%
0.00188
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 4 лет назад

Jenkins Dashboard View Plugin 2.15 and earlier does not escape URLs referenced in Image Dashboard Portlets, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Configure permission.

EPSS

Процентиль: 41%
0.00188
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79