CVE-2017-1000102
Summary
| CVE | CVE-2017-1000102 |
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2017-10-05 01:29:00 UTC |
| Updated | 2017-11-01 19:08:00 UTC |
| Description | The Details view of some Static Analysis Utilities based plugins, was vulnerable to a persisted cross-site scripting vulnerability: Malicious users able to influence the input to these plugins, for example the console output which is parsed to extract build warnings (Warnings Plugin), could insert arbitrary HTML into this view. |
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|
| Jenkins Security Advisory 2017-08-07 |
CONFIRM |
jenkins.io |
Vendor Advisory |
| Malformed Request |
BID |
www.securityfocus.com |
Third Party Advisory, VDB Entry |
| CVE Program record |
CVE.ORG |
www.cve.org |
canonical |
| NVD vulnerability detail |
NVD |
nvd.nist.gov |
canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 997497 Java (Maven) Security Update for org.jvnet.hudson.plugins:analysis-core (GHSA-9c2p-99pg-c4j9)