CVE-2016-0711
published 2016-04-11CVE-2016-0711: Multiple cross-site scripting (XSS) vulnerabilities in Apache Jetspeed before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the title…
PriorityP425medium6.1CVSS 3.0
AVNACLPRNUIRSCCLILAN
EPSS
3.06%
86.1th percentile
Multiple cross-site scripting (XSS) vulnerabilities in Apache Jetspeed before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the title parameter when adding a (1) link, (2) page, or (3) folder resource.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | jetspeed | <= 2.3.0 | — |
CVSS provenance
nvdv3.06.1MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Apache Jetspeed vulnerable to Cross-site Scripting
osv·2022-05-17
CVE-2016-0711 [MEDIUM] Apache Jetspeed vulnerable to Cross-site Scripting
Apache Jetspeed vulnerable to Cross-site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Apache Jetspeed before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the title parameter when adding a (1) link, (2) page, or (3) folder resource.
GHSA
Apache Jetspeed vulnerable to Cross-site Scripting
ghsa·2022-05-17
CVE-2016-0711 [MEDIUM] CWE-79 Apache Jetspeed vulnerable to Cross-site Scripting
Apache Jetspeed vulnerable to Cross-site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Apache Jetspeed before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the title parameter when adding a (1) link, (2) page, or (3) folder resource.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2016-0791 jenkins: Non-constant time comparison of CSRF crumbs (SECURITY-245)
bugzilla·2016-02-25·CVSS 9.8
CVE-2016-0791 [CRITICAL] CVE-2016-0791 jenkins: Non-constant time comparison of CSRF crumbs (SECURITY-245)
CVE-2016-0791 jenkins: Non-constant time comparison of CSRF crumbs (SECURITY-245)
The following flaw was found in Jenkins:
The verification of user-provided CSRF crumbs with the expected value did not use a constant-time comparison algorithm, potentially allowing attackers to use statistical methods to determine valid CSRF crumbs using brute-force methods.
External References:
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-02-24
Discussion:
This issue has been addressed in the following products:
Red Hat OpenShift Enterprise 3.1
Via RHSA-2016:0711 https://access.redhat.com/errata/RHSA-2016:0711
---
This issue has been addressed in the following products:
Red Hat OpenShift Enterprise 2.2
Via RHSA-2016:1773 https://rhn.redhat.com/errata/RHSA-2016-1773
Bugzilla
CVE-2016-0788 jenkins: Remote code execution vulnerability in remoting module (SECURITY-232)
bugzilla·2016-02-25·CVSS 9.8
CVE-2016-0788 [CRITICAL] CVE-2016-0788 jenkins: Remote code execution vulnerability in remoting module (SECURITY-232)
CVE-2016-0788 jenkins: Remote code execution vulnerability in remoting module (SECURITY-232)
The following flaw was found in Jenkins:
A vulnerability in the Jenkins remoting module allowed unauthenticated remote attackers to open a JRMP listener on the server hosting the Jenkins master process, which allowed arbitrary code execution.
External References:
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-02-24
Discussion:
This issue has been addressed in the following products:
Red Hat OpenShift Enterprise 3.1
Via RHSA-2016:0711 https://access.redhat.com/errata/RHSA-2016:0711
---
This issue has been addressed in the following products:
Red Hat OpenShift Enterprise 2.2
Via RHSA-2016:1773 https://rhn.redhat.com/errata/RHSA-2016-1773.html
Bugzilla
CVE-2016-0789 jenkins: HTTP response splitting vulnerability (SECURITY-238)
bugzilla·2016-02-25·CVSS 6.1
CVE-2016-0789 [MEDIUM] CVE-2016-0789 jenkins: HTTP response splitting vulnerability (SECURITY-238)
CVE-2016-0789 jenkins: HTTP response splitting vulnerability (SECURITY-238)
The following flaw was found in Jenkins:
An HTTP response splitting vulnerability in the CLI command documentation allowed attackers to craft Jenkins URLs that serve malicious content.
External References:
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-02-24
Discussion:
This issue has been addressed in the following products:
Red Hat OpenShift Enterprise 3.1
Via RHSA-2016:0711 https://access.redhat.com/errata/RHSA-2016:0711
---
This issue has been addressed in the following products:
Red Hat OpenShift Enterprise 2.2
Via RHSA-2016:1773 https://rhn.redhat.com/errata/RHSA-2016-1773.html
Bugzilla
CVE-2016-0790 jenkins: Non-constant time comparison of API token (SECURITY-241)
bugzilla·2016-02-25·CVSS 5.3
CVE-2016-0790 [MEDIUM] CVE-2016-0790 jenkins: Non-constant time comparison of API token (SECURITY-241)
CVE-2016-0790 jenkins: Non-constant time comparison of API token (SECURITY-241)
The following flaw was found in Jenkins:
The verification of user-provided API tokens with the expected value did not use a constant-time comparison algorithm, potentially allowing attackers to use statistical methods to determine valid API tokens using brute-force methods.
External References:
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-02-24
Discussion:
This issue has been addressed in the following products:
Red Hat OpenShift Enterprise 3.1
Via RHSA-2016:0711 https://access.redhat.com/errata/RHSA-2016:0711
---
This issue has been addressed in the following products:
Red Hat OpenShift Enterprise 2.2
Via RHSA-2016:1773 https://rhn.redhat.com/errata/RHSA-2016-1773.htm
https://mail-archives.apache.org/mod_mbox/portals-jetspeed-user/201603.mbox/%3C73AC0763-D44B-4BDF-867C-05AD4674A62F%40bluesunrise.com%3Ehttps://portals.apache.org/jetspeed-2/security-reports.html#CVE-2016-0711https://mail-archives.apache.org/mod_mbox/portals-jetspeed-user/201603.mbox/%3C73AC0763-D44B-4BDF-867C-05AD4674A62F%40bluesunrise.com%3Ehttps://portals.apache.org/jetspeed-2/security-reports.html#CVE-2016-0711
2016-04-11
Published