Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2017-1000392

Опубликовано: 09 нояб. 2017
Источник: redhat
CVSS3: 3.5
EPSS Низкий

Описание

Jenkins 2.88 and earlier; 2.73.2 and earlier Autocompletion suggestions for text fields were not escaped, resulting in a persisted cross-site scripting vulnerability if the source for the suggestions allowed specifying text that includes HTML metacharacters like less-than and greater-than characters.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Enterprise 3jenkinsWill not fix

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1516791jenkins: Persisted XSS vulnerability in autocompletion suggestions

EPSS

Процентиль: 63%
0.01128
Низкий

3.5 Low

CVSS3

Связанные уязвимости

CVSS3: 4.8
ubuntu
больше 8 лет назад

Jenkins 2.88 and earlier; 2.73.2 and earlier Autocompletion suggestions for text fields were not escaped, resulting in a persisted cross-site scripting vulnerability if the source for the suggestions allowed specifying text that includes HTML metacharacters like less-than and greater-than characters.

CVSS3: 4.8
nvd
больше 8 лет назад

Jenkins 2.88 and earlier; 2.73.2 and earlier Autocompletion suggestions for text fields were not escaped, resulting in a persisted cross-site scripting vulnerability if the source for the suggestions allowed specifying text that includes HTML metacharacters like less-than and greater-than characters.

CVSS3: 4.8
debian
больше 8 лет назад

Jenkins 2.88 and earlier; 2.73.2 and earlier Autocompletion suggestion ...

CVSS3: 4.8
github
больше 4 лет назад

Improper Neutralization of Input During Web Page Generation in Jenkins

EPSS

Процентиль: 63%
0.01128
Низкий

3.5 Low

CVSS3