Lucene search

K
osvGoogleOSV:GHSA-7577-F8FP-5977
HistoryMay 14, 2022 - 2:57 a.m.

Stored Cross-Site Scripting Vulnerability in Jenkins Shelve Project Plugin

2022-05-1402:57:57
Google
osv.dev
6
cross-site scripting
jenkins
shelve project plugin
vulnerability
javascript
ui actions
security

AI Score

6.1

Confidence

High

EPSS

0.001

Percentile

22.0%

A cross-site scripting vulnerability exists in Jenkins Shelve Project Plugin 1.5 and earlier in ShelveProjectAction/index.jelly, ShelvedProjectsAction/index.jelly that allows attackers with Job/Configure permission to define JavaScript that would be executed in another user’s browser when that other user performs some UI actions.

AI Score

6.1

Confidence

High

EPSS

0.001

Percentile

22.0%

Related for OSV:GHSA-7577-F8FP-5977