Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x3rc-cxv7-6xp6

Опубликовано: 14 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 4.7

Описание

Cross-site Scripting in Jenkins Core

Jenkins through 2.93 allows remote authenticated administrators to conduct XSS attacks via a crafted tool name in a job configuration form, as demonstrated by the JDK tool in Jenkins core and the Ant tool in the Ant plugin, aka SECURITY-624.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

< 2.94

2.94

EPSS

Процентиль: 37%
0.00162
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 4.8
redhat
около 8 лет назад

Jenkins through 2.93 allows remote authenticated administrators to conduct XSS attacks via a crafted tool name in a job configuration form, as demonstrated by the JDK tool in Jenkins core and the Ant tool in the Ant plugin, aka SECURITY-624.

CVSS3: 4.7
nvd
около 8 лет назад

Jenkins through 2.93 allows remote authenticated administrators to conduct XSS attacks via a crafted tool name in a job configuration form, as demonstrated by the JDK tool in Jenkins core and the Ant tool in the Ant plugin, aka SECURITY-624.

CVSS3: 4.7
debian
около 8 лет назад

Jenkins through 2.93 allows remote authenticated administrators to con ...

EPSS

Процентиль: 37%
0.00162
Низкий

4.7 Medium

CVSS3

Дефекты

CWE-79