Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:45837
HistoryMar 12, 2024 - 5:46 a.m.

Cross-Site Scripting

2024-03-1205:46:40
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
10
jenkins
vulnerability
build monitor plugin
cross-site scripting
improper sanitization
malicious scripts
security

AI Score

6.6

Confidence

High

EPSS

0

Percentile

9.0%

org.jenkins-ci.plugins, build-monitor-plugin is vulnerable to Cross-site Scripting (XSS). The vulnerability is due improper sanitization of Build Monitor View names, which allows attackers with the ability to configure Build Monitor Views to inject malicious scripts into the view name.

AI Score

6.6

Confidence

High

EPSS

0

Percentile

9.0%