Vulnerability GHSA-28w4-h56g-grg7
Medium Risk
MEDIUM RISK
CVSS Score: 5.4
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
4 years ago
August 24, 2022 at 12:00 AM UTC
Cross-site Scripting in Jenkins Job Configuration History Plugin
1.10.0 - 2.6.0 and 2.8.0 - 2.17.0 and 2.19.0 - 2.30.0
1.10.0 - 2.6.0 and 2.8.0 - 2.17.0 and 2.19.0 - 2.30.0
Summary
Cross-site Scripting in Jenkins Job Configuration History Plugin
Details
Jenkins Job Configuration History Plugin 1165.v8cc9fd1f4597 and earlier does not escape the job name on the System Configuration History page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure job names.
Related Vulnerabilities
Other vulnerabilities affecting the same packages
Medium Risk
3 months ago
Jenkins Job Configuration History Plugin doesn't redact encrypted values of secrets in job and agent configurations
1.10.0 - 2.6.0 and 2.8.0 - 2.17.0 and 2.19.0 - 2.30.0 GHSA-8qr4-27mh-hqfr
1.10.0 - 2.6.0 and 2.8.0 - 2.17.0 and 2.19.0 - 2.30.0 GHSA-8qr4-27mh-hqfr
Medium Risk
3 years ago
XSS vulnerability in Jenkins Job Configuration History Plugin
1.10.0 - 2.6.0 and 2.8.0 - 2.17.0 and 2.19.0 - 2.30.0 GHSA-5jxp-f5rr-g6jc
1.10.0 - 2.6.0 and 2.8.0 - 2.17.0 and 2.19.0 - 2.30.0 GHSA-5jxp-f5rr-g6jc
Medium Risk
3 years ago
Path traversal in Jenkins Job Configuration History Plugin
1.10.0 - 2.6.0 and 2.8.0 - 2.17.0 and 2.19.0 - 2.30.0 GHSA-c7r5-cww9-64q6
1.10.0 - 2.6.0 and 2.8.0 - 2.17.0 and 2.19.0 - 2.30.0 GHSA-c7r5-cww9-64q6
Medium Risk
3 years ago
Path traversal allows exploiting XXE vulnerability in Jenkins Job Configuration History Plugin
1.10.0 - 2.6.0 and 2.8.0 - 2.17.0 and 2.19.0 - 2.30.0 GHSA-cgh7-rgqg-hrcx
1.10.0 - 2.6.0 and 2.8.0 - 2.17.0 and 2.19.0 - 2.30.0 GHSA-cgh7-rgqg-hrcx
High Risk
3 years ago
Job Configuration History Plugin's path traversal allows exploiting XXE vulnerability
1.10.0 - 2.6.0 and 2.8.0 - 2.17.0 and 2.19.0 - 2.30.0 GHSA-ghjw-fcf6-rpr9
1.10.0 - 2.6.0 and 2.8.0 - 2.17.0 and 2.19.0 - 2.30.0 GHSA-ghjw-fcf6-rpr9
Impacted packages
Timeline
Published
4 years ago
August 24, 2022 at 12:00 AM UTC
Last Modified
2 years ago
February 16, 2024 at 08:16 AM UTC