Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-x97g-3gp9-cf2p

Опубликовано: 23 апр. 2022
Источник: github
Github: Прошло ревью
CVSS3: 6.1

Описание

Jenkins allows Cross-Site Scripting (XSS) via Crafted URL

Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL that points to Jenkins.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

< 1.466.2

1.466.2

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 1.467, < 1.482

1.482

EPSS

Процентиль: 71%
0.00659
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 6 лет назад

Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL that points to Jenkins.

redhat
больше 13 лет назад

Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL that points to Jenkins.

CVSS3: 6.1
nvd
около 6 лет назад

Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL that points to Jenkins.

CVSS3: 6.1
debian
около 6 лет назад

Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before ...

EPSS

Процентиль: 71%
0.00659
Низкий

6.1 Medium

CVSS3

Дефекты

CWE-79