漏洞信息
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
Vulnerability Title
N/A
Vulnerability Description
An cross-site scripting vulnerability exists in Jenkins Blue Ocean Plugins 1.10.1 and earlier in blueocean-commons/src/main/java/io/jenkins/blueocean/commons/stapler/Export.java, blueocean-commons/src/main/java/io/jenkins/blueocean/commons/stapler/export/ExportConfig.java, blueocean-commons/src/main/java/io/jenkins/blueocean/commons/stapler/export/JSONDataWriter.java, blueocean-rest-impl/src/main/java/io/jenkins/blueocean/service/embedded/UserStatePreloader.java, blueocean-web/src/main/resources/io/jenkins/blueocean/PageStatePreloadDecorator/header.jelly that allows attackers with permission to edit a user's description in Jenkins to have Blue Ocean render arbitrary HTML when using it as that user.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
CloudBees Jenkins Blue Ocean Plugins 跨站脚本漏洞
Vulnerability Description
Jenkins Blue Ocean Plugins 1.10.1及之前版本中的多个文件存在跨站脚本漏洞。远程攻击者可利用该漏洞注入任意的HTML。(多个文件包括:blueocean-commons/src/main/java/io/jenkins/blueocean/commons/stapler/Export.java、 blueocean-commons/src/main/java/io/jenkins/blueocean/commons/stapler/export/ExportConfig.ja
CVSS Information
N/A
Vulnerability Type
N/A