Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-10432

Опубликовано: 01 окт. 2019
Источник: redhat
CVSS3: 5.4

Описание

Jenkins HTML Publisher Plugin 1.20 and earlier did not escape the project and build display names in the HTML report frame, resulting in a cross-site scripting vulnerability exploitable by users able to change those.

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1764387jenkins-2-plugins: Stored XSS vulnerability in HTML Publisher Plugin

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
почти 7 лет назад

Jenkins HTML Publisher Plugin 1.20 and earlier did not escape the project and build display names in the HTML report frame, resulting in a cross-site scripting vulnerability exploitable by users able to change those.

CVSS3: 5.4
github
больше 4 лет назад

Jenkins HTML Publisher Plugin vulnerable to Cross-site Scripting

5.4 Medium

CVSS3