Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-65934
HistoryJun 24, 2022 - 12:00 a.m.

Jenkins Dynamic Extended Choice Parameter Plugin Cross-Site Scripting Vulnerability

2022-06-2400:00:00
China National Vulnerability Database
www.cnvd.org.cn
11

0.001 Low

EPSS

Percentile

22.0%

Jenkins and Jenkins Plugin are both Jenkins open source products.Jenkins is an application. Jenkins Plugin is an application that provides hundreds of plugins to support building, deploying, and automating any project. Jenkins Dynamic Extended Choice Parameter Plugin version 1.0.1 and prior versions are vulnerable to cross-site scripting. The vulnerability stems from a failure to escape the name and description of the Moded Extended Choice parameter on the view where the parameter is displayed, and can be exploited by attackers to execute JavaScript code on the client side.

0.001 Low

EPSS

Percentile

22.0%

Related for CNVD-2022-65934