Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-w43x-5f8f-686p

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 8

Описание

Stored XSS vulnerability in multiple axis builds tooltips in Jenkins Matrix Project Plugin

Matrix Project Plugin 1.16 and earlier does not escape the axis names shown in tooltips on the overview page of builds with multiple axes. This results in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission.

Matrix Project Plugin 1.17 escapes the axis names shown in these tooltips.

Пакеты

Наименование

org.jenkins-ci.plugins:matrix-project

maven
Затронутые версииВерсия исправления

<= 1.16

1.17

EPSS

Процентиль: 53%
0.00304
Низкий

8 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 8
redhat
больше 5 лет назад

Jenkins Matrix Project Plugin 1.16 and earlier does not escape the axis names shown in tooltips on the overview page of builds with multiple axes, resulting in a stored cross-site scripting vulnerability.

CVSS3: 5.4
nvd
больше 5 лет назад

Jenkins Matrix Project Plugin 1.16 and earlier does not escape the axis names shown in tooltips on the overview page of builds with multiple axes, resulting in a stored cross-site scripting vulnerability.

EPSS

Процентиль: 53%
0.00304
Низкий

8 High

CVSS3

Дефекты

CWE-79