Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-6374

Опубликовано: 21 нояб. 2013
Источник: redhat
CVSS2: 4.3
EPSS Низкий

Описание

Cross-site scripting (XSS) vulnerability in the Build Failure Analyzer plugin before 1.5.1 for Jenkins allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

Отчет

Not affected. This issue did not affect Jenkins as shipped with various Red Hat products, as they do not include the Jenkins Build Failure Analyzer plugin.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Enterprise 1jenkinsNot affected
Red Hat OpenShift Enterprise 2jenkinsNot affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1032400Jenkins: XSS vulnerability in Build failure analyzer plugin (SECURITY-96)

EPSS

Процентиль: 42%
0.00201
Низкий

4.3 Medium

CVSS2

Связанные уязвимости

ubuntu
около 12 лет назад

Cross-site scripting (XSS) vulnerability in the Build Failure Analyzer plugin before 1.5.1 for Jenkins allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

nvd
около 12 лет назад

Cross-site scripting (XSS) vulnerability in the Build Failure Analyzer plugin before 1.5.1 for Jenkins allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

debian
около 12 лет назад

Cross-site scripting (XSS) vulnerability in the Build Failure Analyzer ...

github
больше 3 лет назад

Jenkins Build Failure Analyzer Plugin allows Cross-Site Scripting (XSS)

EPSS

Процентиль: 42%
0.00201
Низкий

4.3 Medium

CVSS2