Описание
A reflected cross site scripting vulnerability in Jenkins ElectricFlow Plugin 1.1.6 and earlier allowed attackers able to control the output of the ElectricFlow API to inject arbitrary HTML and JavaScript in job configuration forms containing post-build steps provided by this plugin.
Ссылки
- Mailing ListThird Party Advisory
- Vendor Advisory
- Mailing ListThird Party Advisory
- Vendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 1.1.6 (включая)
cpe:2.3:a:jenkins:electricflow:*:*:*:*:*:jenkins:*:*
EPSS
Процентиль: 20%
0.00065
Низкий
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79
Связанные уязвимости
CVSS3: 4.7
github
больше 3 лет назад
Jenkins ElectricFlow Plugin is vulnerable to reflected cross site scripting vulnerability
EPSS
Процентиль: 20%
0.00065
Низкий
6.1 Medium
CVSS3
4.3 Medium
CVSS2
Дефекты
CWE-79