Lucene search

K
cnvdChina National Vulnerability DatabaseCNVD-2022-84064
HistoryMar 17, 2022 - 12:00 a.m.

Jenkins Extended Choice Parameter Plugin Cross-Site Scripting Vulnerability

2022-03-1700:00:00
China National Vulnerability Database
www.cnvd.org.cn
17

0.001 Low

EPSS

Percentile

22.0%

Jenkins and Jenkins Plugin are both products of Jenkins. jenkins is an application. Jenkins Plugin is an application that provides hundreds of plugins to support building, deploying, and automating any project. The vulnerability stems from the plugin’s failure to escape the value and description of an Extended Choice parameter of parameter type Radio Buttons or Check Boxes, which could be exploited to cause a stored cross-site scripting attack.

0.001 Low

EPSS

Percentile

22.0%