Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:5757
HistoryJan 29, 2018 - 12:31 a.m.

Cross-site Scripting (XSS)

2018-01-2900:31:16
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
2

0.001 Low

EPSS

Percentile

34.2%

global-build-stats is vulnerable to reflected cross-site scripting (XSS) attacks. These attacks are possible because some URLs return JSON as Content Type: text/html. This content may be interpreted by clients as HTML allowing XSS to be performed. Cross-site request forgery (CSRF) attacks are also possible because some URLs don’t require POST requests to modify data.

CPENameOperatorVersion
hudson global-build-stats pluginle1.0

0.001 Low

EPSS

Percentile

34.2%

Related for VERACODE:5757