Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q87g-7mp5-765q

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Improper Neutralization of Input During Web Page Generation in Jenkins Script Security Plugin

Jenkins Script Security Plugin 1.72 and earlier does not correctly escape pending or approved classpath entries on the In-process Script Approval page, resulting in a stored cross-site scripting vulnerability.

Пакеты

Наименование

org.jenkins-ci.plugins:script-security

maven
Затронутые версииВерсия исправления

<= 1.72

1.73

EPSS

Процентиль: 31%
0.0012
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
redhat
больше 5 лет назад

Jenkins Script Security Plugin 1.72 and earlier does not correctly escape pending or approved classpath entries on the In-process Script Approval page, resulting in a stored cross-site scripting vulnerability.

CVSS3: 5.4
nvd
больше 5 лет назад

Jenkins Script Security Plugin 1.72 and earlier does not correctly escape pending or approved classpath entries on the In-process Script Approval page, resulting in a stored cross-site scripting vulnerability.

EPSS

Процентиль: 31%
0.0012
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79