Lucene search

K
cve[email protected]CVE-2011-4344
HistoryDec 01, 2011 - 11:55 a.m.

CVE-2011-4344

2011-12-0111:55:07
CWE-79
web.nvd.nist.gov
19
cve-2011-4344
xss
jenkins core
jenkins
vulnerability
web script
html
error messages

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

5.7 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

68.3%

Cross-site scripting (XSS) vulnerability in Jenkins Core in Jenkins before 1.438, and 1.409 LTS before 1.409.3 LTS, when a stand-alone container is used, allows remote attackers to inject arbitrary web script or HTML via vectors related to error messages.

Affected configurations

NVD
Node
jenkinsjenkinsMatch1.409.1lts
OR
jenkinsjenkinsMatch1.409.2lts
Node
jenkinsjenkinsRange1.437

2.6 Low

CVSS2

Attack Vector

NETWORK

Attack Complexity

HIGH

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:H/Au:N/C:N/I:P/A:N

5.7 Medium

AI Score

Confidence

High

0.003 Low

EPSS

Percentile

68.3%

Related for CVE-2011-4344