Description
Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not escape the SCM tag name on the tooltip for SCM tag actions, resulting in a stored XSS vulnerability exploitable by users able to control SCM tag names for these actions.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-2974 | Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not escape the SCM tag name on the tooltip for SCM tag actions, resulting in a stored XSS vulnerability exploitable by users able to control SCM tag names for these actions. |
Github GHSA |
GHSA-7cjc-xppr-xj6x | Improper Neutralization of Input During Web Page Generation in Jenkins |
References
History
No history.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-04T22:24:17.504Z
Reserved: 2019-03-29T00:00:00.000Z
Link: CVE-2019-10403
No data.
Status : Modified
Published: 2019-09-25T16:15:10.570
Modified: 2024-11-21T04:19:03.650
Link: CVE-2019-10403
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA