Логотип exploitDog
bind:CVE-2018-1999007
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2018-1999007

Количество 4

Количество 4

redhat логотип

CVE-2018-1999007

больше 7 лет назад

A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers with the ability to control the existence of some URLs in Jenkins to define JavaScript that would be executed in another user's browser when that other user views HTTP 404 error pages while Stapler debug mode is enabled.

CVSS3: 4.7
EPSS: Низкий
nvd логотип

CVE-2018-1999007

больше 7 лет назад

A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers with the ability to control the existence of some URLs in Jenkins to define JavaScript that would be executed in another user's browser when that other user views HTTP 404 error pages while Stapler debug mode is enabled.

CVSS3: 5.4
EPSS: Низкий
debian логотип

CVE-2018-1999007

больше 7 лет назад

A cross-site scripting vulnerability exists in Jenkins 2.132 and earli ...

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-6456-xjm5-g3pg

больше 3 лет назад

Cross-site scripting vulnerability exists in Jenkins and Stapler Plugin

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
redhat логотип
CVE-2018-1999007

A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers with the ability to control the existence of some URLs in Jenkins to define JavaScript that would be executed in another user's browser when that other user views HTTP 404 error pages while Stapler debug mode is enabled.

CVSS3: 4.7
0%
Низкий
больше 7 лет назад
nvd логотип
CVE-2018-1999007

A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers with the ability to control the existence of some URLs in Jenkins to define JavaScript that would be executed in another user's browser when that other user views HTTP 404 error pages while Stapler debug mode is enabled.

CVSS3: 5.4
0%
Низкий
больше 7 лет назад
debian логотип
CVE-2018-1999007

A cross-site scripting vulnerability exists in Jenkins 2.132 and earli ...

CVSS3: 5.4
0%
Низкий
больше 7 лет назад
github логотип
GHSA-6456-xjm5-g3pg

Cross-site scripting vulnerability exists in Jenkins and Stapler Plugin

CVSS3: 5.4
0%
Низкий
больше 3 лет назад

Уязвимостей на страницу