Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-66001
HistoryJun 24, 2022 - 12:00 a.m.

Jenkins Filesystem List Parameter Plugin Cross-Site Scripting Vulnerability

2022-06-2400:00:00
China National Vulnerability Database
www.cnvd.org.cn
20

0.001 Low

EPSS

Percentile

22.0%

Jenkins and Jenkins Plugin are both Jenkins open source products. jenkins is an application. Jenkins Plugin is an application that provides hundreds of plug-ins to support building, deploying, and automating any project. Jenkins Filesystem List Parameter Plugin version 0.0.7 and earlier versions are vulnerable to cross-site scripting. The vulnerability stems from a failure to escape the name and description of the filesystem object list parameter on the view where the parameter is displayed, and can be exploited by attackers to execute JavaScript code on the client side.

0.001 Low

EPSS

Percentile

22.0%