Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-84058
HistoryMar 17, 2022 - 12:00 a.m.

Jenkins List Git Branches Parameter Plugin Cross-Site Scripting Vulnerability

2022-03-1700:00:00
China National Vulnerability Database
www.cnvd.org.cn
7

0.001 Low

EPSS

Percentile

22.0%

Jenkins and Jenkins Plugin are both products of Jenkins, which is an application. Jenkins Plugin is an application that provides hundreds of plugins to support building and deploying projects, and the Jenkins List Git Branches Parameter Plugin 0.0.9 and earlier is vulnerable to a cross-site scripting vulnerability caused by the plugin’s failure to escape the names of List Git Branchs parameter names. An attacker with view/configuration privileges could exploit this vulnerability to cause a stored cross-site scripting attack.

0.001 Low

EPSS

Percentile

22.0%

Related for CNVD-2022-84058