Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p2fr-mq9m-6w6p

Опубликовано: 15 фев. 2023
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Cross-site Scripting in Jenkins Email Extension Plugin

Jenkins Email Extension Plugin 2.93 and earlier does not escape, sanitize, or sandbox rendered email template output or log output generated during template rendering, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create or change custom email templates.

Пакеты

Наименование

org.jenkins-ci.plugins:email-ext

maven
Затронутые версииВерсия исправления

<= 2.93

2.94

EPSS

Процентиль: 92%
0.07556
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
почти 3 года назад

Jenkins Email Extension Plugin 2.93 and earlier does not escape, sanitize, or sandbox rendered email template output or log output generated during template rendering, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create or change custom email templates.

EPSS

Процентиль: 92%
0.07556
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79