Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-mhp7-3393-pfqr

Опубликовано: 24 июн. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8

Описание

Cross-site Scripting vulnerability in Jenkins

Since Jenkins 2.340, symbol-based icons unescape previously escaped values of tooltip parameters.

This vulnerability is known to be exploitable by attackers with Job/Configure permission.

Jenkins 2.356, LTS 2.332.4 and LTS 2.346.1 addresses this vulnerability. Symbol-based icons no longer unescape values of tooltip parameters.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 2.340, < 2.356

2.356

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 2.332, < 2.332.4

2.332.4

EPSS

Процентиль: 91%
0.06403
Низкий

8 High

CVSS3

Дефекты

CWE-22
CWE-79

Связанные уязвимости

CVSS3: 6.1
redhat
больше 3 лет назад

In Jenkins 2.340 through 2.355 (both inclusive) symbol-based icons unescape previously escaped values of 'tooltip' parameters, resulting in a cross-site scripting (XSS) vulnerability.

CVSS3: 5.4
nvd
больше 3 лет назад

In Jenkins 2.340 through 2.355 (both inclusive) symbol-based icons unescape previously escaped values of 'tooltip' parameters, resulting in a cross-site scripting (XSS) vulnerability.

CVSS3: 5.4
debian
больше 3 лет назад

In Jenkins 2.340 through 2.355 (both inclusive) symbol-based icons une ...

EPSS

Процентиль: 91%
0.06403
Низкий

8 High

CVSS3

Дефекты

CWE-22
CWE-79