Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p5jh-8rxp-wqjj

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8

Описание

XSS vulnerability in Jenkins Build Failure Analyzer Plugin

Jenkins Build Failure Analyzer Plugin 1.27.0 and earlier does not escape matching text in a form validation response, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able to provide console output for builds used to test build log indications.

Build Failure Analyzer Plugin 1.27.1 escapes matching text in the affected form validation response.

Пакеты

Наименование

com.sonyericsson.jenkins.plugins.bfa:build-failure-analyzer

maven
Затронутые версииВерсия исправления

<= 1.27.0

1.27.1

EPSS

Процентиль: 39%
0.00171
Низкий

8 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 5 лет назад

Jenkins Build Failure Analyzer Plugin 1.27.0 and earlier does not escape matching text in a form validation response, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able to provide console output for builds used to test build log indications.

EPSS

Процентиль: 39%
0.00171
Низкий

8 High

CVSS3

Дефекты

CWE-79