Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q9g4-9fx4-v533

Опубликовано: 22 сент. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8.8

Описание

Stored XSS vulnerability in Jenkins DotCi Plugin

DotCi Plugin 2.40.00 and earlier does not escape the GitHub user name parameter provided to commit notifications when displaying them in a build cause.

This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to submit crafted commit notifications to the /githook/ endpoint (see also SECURITY-2867).

This vulnerability is only exploitable in Jenkins 2.314 and earlier, LTS 2.303.1 and earlier. See the LTS upgrade guide.

Пакеты

Наименование

com.groupon.jenkins-ci.plugins:DotCi

maven
Затронутые версииВерсия исправления

<= 2.40.00

Отсутствует

EPSS

Процентиль: 95%
0.20595
Средний

8.8 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 3 лет назад

Jenkins DotCi Plugin 2.40.00 and earlier does not escape the GitHub user name parameter provided to commit notifications when displaying them in a build cause, resulting in a stored cross-site scripting (XSS) vulnerability.

EPSS

Процентиль: 95%
0.20595
Средний

8.8 High

CVSS3

Дефекты

CWE-79