Lucene search

K
prionPRIOn knowledge basePRION:CVE-2017-2601
HistoryMay 10, 2018 - 1:29 p.m.

Cross site scripting

2018-05-1013:29:00
PRIOn knowledge base
www.prio-n.com
12

5.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

50.7%

Jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted cross-site scripting in parameter names and descriptions (SECURITY-353). Users with the permission to configure jobs were able to inject JavaScript into parameter names and descriptions.

CPENameOperatorVersion
jenkinslt2.32.2
jenkinslt2.44

5.2 Medium

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

50.7%