Количество 2
Количество 2
CVE-2023-28669
Jenkins JaCoCo Plugin 3.3.2 and earlier does not escape class and method names shown on the UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control input files for the 'Record JaCoCo coverage report' post-build action.
GHSA-xj29-gfww-j67g
Jenkins JaCoCo Plugin vulnerable to Stored Cross-site Scripting
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-28669 Jenkins JaCoCo Plugin 3.3.2 and earlier does not escape class and method names shown on the UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control input files for the 'Record JaCoCo coverage report' post-build action. | CVSS3: 5.4 | 4% Низкий | почти 3 года назад | |
GHSA-xj29-gfww-j67g Jenkins JaCoCo Plugin vulnerable to Stored Cross-site Scripting | CVSS3: 8 | 4% Низкий | почти 3 года назад |
Уязвимостей на страницу