Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:39571
HistoryMar 07, 2023 - 12:49 a.m.

Cross-site Scripting (XSS)

2023-03-0700:49:52
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8
jenkins-2-plugins
cross-site scripting
http urls
test report
clickable links
stored vulnerability
item permission
configure permission
software

0.001 Low

EPSS

Percentile

33.3%

jenkins-2-plugins is vulnerable to Cross-site Scripting (XSS) attacks. The library converts HTTP(S) URLs in test report output to clickable links in an unsafe manner, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.