Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-wv63-gwr9-5c55

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

Stored XSS vulnerability in Jenkins button labels

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape button labels in the Jenkins UI.

This results in a cross-site scripting vulnerability exploitable by attackers with the ability to control button labels. An example of buttons with a user-controlled label are the buttons of the Pipeline input step.

Jenkins 2.275, LTS 2.263.2 escapes button labels in the Jenkins UI.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

< 2.263.1

2.275

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 2.263.2, <= 2.274

2.275

EPSS

Процентиль: 67%
0.0054
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
redhat
около 5 лет назад

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape button labels in the Jenkins UI, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with the ability to control button labels.

CVSS3: 5.4
nvd
около 5 лет назад

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape button labels in the Jenkins UI, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with the ability to control button labels.

CVSS3: 5.4
debian
около 5 лет назад

Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape but ...

EPSS

Процентиль: 67%
0.0054
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79