Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:45822
HistoryMar 11, 2024 - 5:22 a.m.

Cross-site Scripting (XSS)

2024-03-1105:22:10
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
8
xss vulnerability
jenkins
htmlpublisher
input sanitization
malicious scripts
item/configure permission

AI Score

6.8

Confidence

High

EPSS

0

Percentile

9.0%

org.jenkins-ci.plugins, htmlpublisher is vulnerable to Cross-Site Scripting. The vulnerability is due to publishReports function within HtmlPublisher.java not having proper input sanitization, This flow allows attackers with Item/Configure permission to inject malicious scripts into job names, report names, and index page titles displayed as part of the report frame.

AI Score

6.8

Confidence

High

EPSS

0

Percentile

9.0%