Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xpvp-h73c-m9rq

Опубликовано: 22 сент. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8

Описание

Jenkins vulnerable to stored cross site scripting in the I:helpIcon component

Jenkins 2.367 through 2.369 (both inclusive) does not escape tooltips of the l:helpIcon UI component used for some help icons on the Jenkins web UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control tooltips for this component.

As of publication, the Jenkins security team is unaware of any exploitable help icon/tooltip in Jenkins core or plugins published by the Jenkins project. The vast majority of help icons use the l:help component instead of l:helpIcon. The few known instances of l:helpIcon do not have user-controllable tooltip contents.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 2.367, < 2.370

2.370

EPSS

Процентиль: 87%
0.03363
Низкий

8 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 7.4
redhat
больше 3 лет назад

Jenkins 2.367 through 2.369 (both inclusive) does not escape tooltips of the l:helpIcon UI component used for some help icons on the Jenkins web UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control tooltips for this component.

CVSS3: 5.4
nvd
больше 3 лет назад

Jenkins 2.367 through 2.369 (both inclusive) does not escape tooltips of the l:helpIcon UI component used for some help icons on the Jenkins web UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control tooltips for this component.

CVSS3: 5.4
debian
больше 3 лет назад

Jenkins 2.367 through 2.369 (both inclusive) does not escape tooltips ...

EPSS

Процентиль: 87%
0.03363
Низкий

8 High

CVSS3

Дефекты

CWE-79