Description
A cross-site scripting vulnerability exists in Jenkins CppNCSS Plugin 1.1 and earlier in AbstractProjectAction/index.jelly that allow an attacker to craft links to Jenkins URLs that run arbitrary JavaScript in the user's browser when accessed.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5785 | A cross-site scripting vulnerability exists in Jenkins CppNCSS Plugin 1.1 and earlier in AbstractProjectAction/index.jelly that allow an attacker to craft links to Jenkins URLs that run arbitrary JavaScript in the user's browser when accessed. |
Github GHSA |
GHSA-xgmh-rvpw-6498 | Reflected cross-site-scripting vulnerability in report URL of Jenkins CppNCSS Plugin |
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-16T20:06:26.019Z
Reserved: 2018-03-13T00:00:00.000Z
Link: CVE-2018-1000108
No data.
Status : Modified
Published: 2018-03-13T13:29:00.547
Modified: 2024-11-21T03:39:39.687
Link: CVE-2018-1000108
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA