VulnerabilityModified
CVE-2017-1000404
The Jenkins Delivery Pipeline Plugin version 1.0.7 and earlier used the unescaped content of the query parameter 'fullscreen' in its JavaScript, resulting in a cross-site scripting vulnerability through specially crafted URLs.
MEDIUM 6.1EPSS 0.95%
Does this matter?
Lower severity and a low EPSS score (0.95%). Track it; it rarely justifies an emergency change on its own.
Description
The Jenkins Delivery Pipeline Plugin version 1.0.7 and earlier used the unescaped content of the query parameter 'fullscreen' in its JavaScript, resulting in a cross-site scripting vulnerability through specially crafted URLs.
- CVSS 3.0
- 6.1 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.95% probability · 59th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- jenkins/delivery pipeline
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/bid/101927Third Party Advisory, VDB Entry
- https://jenkins.io/security/advisory/2017-11-16/Vendor Advisory
- http://www.securityfocus.com/bid/101927Third Party Advisory, VDB Entry
- https://jenkins.io/security/advisory/2017-11-16/Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.