Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:45840
HistoryMar 12, 2024 - 7:03 a.m.

Cross Site Scripting(XSS)

2024-03-1207:03:19
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
15
jenkins
html publisher plugin
cross site scripting
input sanitization
attackers
permission
file system

AI Score

5.6

Confidence

High

EPSS

0

Percentile

9.0%

Jenkins HTML Publisher Plugin is vulnerable to Cross Site Scripting (XSS). The vulnerability is due to improper input sanitization, allowing attackers with Item/Configure permission to execute XSS attacks and determine the existence of paths on the Jenkins controller file system.

AI Score

5.6

Confidence

High

EPSS

0

Percentile

9.0%