Описание
Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL that points to Jenkins.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Enterprise 1 | jenkins | Affected |
Показывать по
10
Дополнительная информация
Статус:
Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=859304Jenkins: core allows XSS
4.3 Medium
CVSS2
Связанные уязвимости
CVSS3: 6.1
ubuntu
около 6 лет назад
Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL that points to Jenkins.
CVSS3: 6.1
nvd
около 6 лет назад
Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL that points to Jenkins.
CVSS3: 6.1
debian
около 6 лет назад
Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before ...
CVSS3: 6.1
github
почти 4 года назад
Jenkins allows Cross-Site Scripting (XSS) via Crafted URL
4.3 Medium
CVSS2