Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-qpg9-83fv-x9ch

Опубликовано: 13 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Improper Neutralization of Input During Web Page Generation in Jenkins

The f:validateButton form control for the Jenkins UI did not properly escape job URLs in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, resulting in a cross-site scripting (XSS) vulnerability exploitable by users with the ability to control job names.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

<= 2.164.1

2.164.2

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 2.165, <= 2.171

2.172

EPSS

Процентиль: 76%
0.00967
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
redhat
почти 7 лет назад

The f:validateButton form control for the Jenkins UI did not properly escape job URLs in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, resulting in a cross-site scripting (XSS) vulnerability exploitable by users with the ability to control job names.

CVSS3: 5.4
nvd
почти 7 лет назад

The f:validateButton form control for the Jenkins UI did not properly escape job URLs in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, resulting in a cross-site scripting (XSS) vulnerability exploitable by users with the ability to control job names.

CVSS3: 5.4
debian
почти 7 лет назад

The f:validateButton form control for the Jenkins UI did not properly ...

EPSS

Процентиль: 76%
0.00967
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79