[MAVEN:GHSA-Q5F8-FXRX-PW6F] Jenkins subject to Cross-site Scripting

Severity Moderate
Affected Packages 1
Fixed Packages 1
CVEs 1

Cross-site scripting (XSS) vulnerability in Jenkins before 1.502 and LTS before 1.480.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Package Affected Version
pkg:maven/org.jenkins-ci.main/jenkins-core < 1.502
Package Fixed Version
pkg:maven/org.jenkins-ci.main/jenkins-core = 1.502
ID
MAVEN:GHSA-Q5F8-FXRX-PW6F
Severity
moderate
URL
https://github.com/advisories/GHSA-q5f8-fxrx-pw6f
Published
2022-05-05T02:48:48
(2 years ago)
Modified
2023-02-04T00:30:44
(19 months ago)
Rights
Maven Security Team
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.main/jenkins-core org.jenkins-ci.main jenkins-core < 1.502
Fixed pkg:maven/org.jenkins-ci.main/jenkins-core org.jenkins-ci.main jenkins-core = 1.502
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...