Количество 2
Количество 2
CVE-2023-28670
Jenkins Pipeline Aggregator View Plugin 1.13 and earlier does not escape a variable representing the current view's URL in inline JavaScript, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by authenticated attackers with Overall/Read permission.
GHSA-v27q-87jf-j9cr
Jenkins Pipeline Aggregator View Plugin vulnerable to Cross-site Scripting
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2023-28670 Jenkins Pipeline Aggregator View Plugin 1.13 and earlier does not escape a variable representing the current view's URL in inline JavaScript, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by authenticated attackers with Overall/Read permission. | CVSS3: 5.4 | 3% Низкий | почти 3 года назад | |
GHSA-v27q-87jf-j9cr Jenkins Pipeline Aggregator View Plugin vulnerable to Cross-site Scripting | CVSS3: 8 | 3% Низкий | почти 3 года назад |
Уязвимостей на страницу