Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xqpp-26pp-2365

Опубликовано: 24 мая 2022
Источник: github
Github: Прошло ревью
CVSS3: 5.4

Описание

XSS vulnerability in Jenkins Markdown Formatter Plugin

Jenkins Markdown Formatter Plugin 0.1.0 and earlier uses a Markdown library to parse Markdown that does not escape crafted link target URLs.

This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with the ability to edit any description rendered using the configured markup formatter.

Jenkins Markdown Formatter Plugin 0.2.0 uses a different Markdown library that is not affected by this problem.

Пакеты

Наименование

io.jenkins.plugins:markdown-formatter

maven
Затронутые версииВерсия исправления

<= 0.1.0

0.2.0

EPSS

Процентиль: 48%
0.00246
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
nvd
больше 4 лет назад

Jenkins Markdown Formatter Plugin 0.1.0 and earlier does not sanitize crafted link target URLs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with the ability to edit any description rendered using the configured markup formatter.

EPSS

Процентиль: 48%
0.00246
Низкий

5.4 Medium

CVSS3

Дефекты

CWE-79