Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-1000392

Опубликовано: 09 нояб. 2017
Источник: redhat
CVSS3: 3.5

Описание

Jenkins 2.88 and earlier; 2.73.2 and earlier Autocompletion suggestions for text fields were not escaped, resulting in a persisted cross-site scripting vulnerability if the source for the suggestions allowed specifying text that includes HTML metacharacters like less-than and greater-than characters.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Enterprise 3jenkinsWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1516791jenkins: Persisted XSS vulnerability in autocompletion suggestions

3.5 Low

CVSS3

Связанные уязвимости

CVSS3: 4.8
ubuntu
около 8 лет назад

Jenkins 2.88 and earlier; 2.73.2 and earlier Autocompletion suggestions for text fields were not escaped, resulting in a persisted cross-site scripting vulnerability if the source for the suggestions allowed specifying text that includes HTML metacharacters like less-than and greater-than characters.

CVSS3: 4.8
nvd
около 8 лет назад

Jenkins 2.88 and earlier; 2.73.2 and earlier Autocompletion suggestions for text fields were not escaped, resulting in a persisted cross-site scripting vulnerability if the source for the suggestions allowed specifying text that includes HTML metacharacters like less-than and greater-than characters.

CVSS3: 4.8
debian
около 8 лет назад

Jenkins 2.88 and earlier; 2.73.2 and earlier Autocompletion suggestion ...

CVSS3: 4.8
github
больше 3 лет назад

Improper Neutralization of Input During Web Page Generation in Jenkins

3.5 Low

CVSS3