Lucene search

K
githubGitHub Advisory DatabaseGHSA-5J5R-6MV9-M255
HistoryMar 06, 2024 - 6:30 p.m.

Jenkins Build Monitor View Plugin vulnerable to stored Cross-site Scripting

2024-03-0618:30:38
CWE-79
GitHub Advisory Database
github.com
16
jenkins
build monitor view
xss
vulnerability
stored
cross-site scripting
security
software

AI Score

5.5

Confidence

High

EPSS

0

Percentile

9.0%

Jenkins Build Monitor View Plugin 1.14-860.vd06ef2568b_3f and earlier does not escape Build Monitor View names, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure Build Monitor Views.

Affected configurations

Vulners
Node
org.jenkins-ci.pluginsbuild-monitor-pluginRange1.14-860.vd06ef2568b
VendorProductVersionCPE
org.jenkins-ci.pluginsbuild-monitor-plugin*cpe:2.3:a:org.jenkins-ci.plugins:build-monitor-plugin:*:*:*:*:*:*:*:*

AI Score

5.5

Confidence

High

EPSS

0

Percentile

9.0%