Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-84060
HistoryMar 17, 2022 - 12:00 a.m.

Jenkins global-build-stats Plugin Cross-Site Scripting Vulnerability

2022-03-1700:00:00
China National Vulnerability Database
www.cnvd.org.cn
10

0.001 Low

EPSS

Percentile

22.0%

Jenkins and Jenkins Plugin are both products of Jenkins, which is an application. Jenkins Plugin is an application that provides hundreds of plugins to support building and deploying projects. The vulnerability is caused by the plugin’s failure to escape multiple fields in the chart configuration on the Global Build Stats page, which could be exploited to cause an XSS (stored cross-site scripting) attack.

CPENameOperatorVersion
jenkins global-build-stats pluginle1.5

0.001 Low

EPSS

Percentile

22.0%

Related for CNVD-2022-84060