Описание
A stored cross site scripting vulnerability in Jenkins ElectricFlow Plugin 1.1.5 and earlier allowed attackers able to configure jobs in Jenkins or control the output of the ElectricFlow API to inject arbitrary HTML and JavaScript in the plugin-provided output on build status pages.
Ссылки
- Mailing ListThird Party Advisory
- Vendor Advisory
- Mailing ListThird Party Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.1.6 (включая)
cpe:2.3:a:jenkins:electricflow:*:*:*:*:*:jenkins:*:*
EPSS
Процентиль: 18%
0.00058
Низкий
5.4 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 5.4
github
больше 3 лет назад
Jenkins ElectricFlow Plugin is vulnerable to stored cross site scripting vulnerability
EPSS
Процентиль: 18%
0.00058
Низкий
5.4 Medium
CVSS3
3.5 Low
CVSS2
Дефекты
CWE-79