Lucene search

K
osvGoogleOSV:GHSA-3RRG-P8XC-3457
HistoryMay 14, 2022 - 3:33 a.m.

Stored cross-site scripting vulnerability in Jenkins TestLink Plugin

2022-05-1403:33:40
Google
osv.dev
5

5.9 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.0%

A cross-site scripting vulnerability exists in Jenkins TestLink Plugin 2.12 and earlier in TestLinkBuildAction/summary.jelly and others that allow an attacker who can control e.g. TestLink report names to have Jenkins serve arbitrary HTML and JavaScript

CPENameOperatorVersion
org.jenkins-ci.plugins:testlinkeq2.5.1

5.9 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

22.0%

Related for OSV:GHSA-3RRG-P8XC-3457