Логотип exploitDog
bind:CVE-2022-43420
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2022-43420

Количество 2

Количество 2

nvd логотип

CVE-2022-43420

больше 3 лет назад

Jenkins Contrast Continuous Application Security Plugin 3.9 and earlier does not escape data returned from the Contrast service when generating a report, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control or modify Contrast service API responses.

CVSS3: 5.4
EPSS: Средний
github логотип

GHSA-hvcr-927w-qcvq

больше 3 лет назад

Stored XSS vulnerability in Jenkins Contrast Continuous Application Security Plugin

CVSS3: 7.5
EPSS: Средний

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2022-43420

Jenkins Contrast Continuous Application Security Plugin 3.9 and earlier does not escape data returned from the Contrast service when generating a report, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control or modify Contrast service API responses.

CVSS3: 5.4
11%
Средний
больше 3 лет назад
github логотип
GHSA-hvcr-927w-qcvq

Stored XSS vulnerability in Jenkins Contrast Continuous Application Security Plugin

CVSS3: 7.5
11%
Средний
больше 3 лет назад

Уязвимостей на страницу