Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:36765
HistoryAug 20, 2022 - 9:46 a.m.

Cross-site Scripting (XSS)

2022-08-2009:46:18
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8
jenkins
xss
vulnerability
help icon
tooltip
arbitrary javascript
software

0.001 Low

EPSS

Percentile

22.0%

jenkins is vulnerable to cross-site scripting. The vulnerability exists because the help icon does not escape the feature name that is part of its tooltip which allows an attacker to inject and execute arbitrary javascript.