Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-65932
HistoryJun 24, 2022 - 12:00 a.m.

Jenkins CRX Content Package Deployer Plugin Cross-Site Scripting Vulnerability

2022-06-2400:00:00
China National Vulnerability Database
www.cnvd.org.cn
9

0.001 Low

EPSS

Percentile

22.0%

Jenkins and Jenkins Plugin are both Jenkins open source products.Jenkins is an application. Jenkins Plugin is an application that provides hundreds of plug-ins to support building, deploying, and automating any project. a cross-site scripting vulnerability exists in Jenkins CRX Content Package Deployer Plugin version 1.9 and earlier. The vulnerability stems from a failure to escape the name and description of the CRX Content Package Choice parameter on the view where the parameter is displayed, and can be exploited by attackers to execute JavaScript code on the client side.

0.001 Low

EPSS

Percentile

22.0%

Related for CNVD-2022-65932