Cross-site scripting (XSS) vulnerability in the Extra Columns plugin before 1.17 in Jenkins allows remote attackers to inject arbitrary web script or HTML by leveraging failure to filter tool tips through the configured markup formatter.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2016-4156 | Jenkins Extra Columns Plugin allows Cross-Site Scripting (XSS) |
Github GHSA |
GHSA-mr4j-7jjv-24m7 | Jenkins Extra Columns Plugin allows Cross-Site Scripting (XSS) |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-05T23:47:56.875Z
Reserved: 2016-03-10T00:00:00
Link: CVE-2016-3101
No data.
Status : Deferred
Published: 2017-02-09T15:59:00.973
Modified: 2025-04-20T01:37:25.860
Link: CVE-2016-3101
OpenCVE Enrichment
No data.
EUVD
Github GHSA