cbcvebase.
CVE-2016-4988
published 2017-02-09

CVE-2016-4988: Cross-site scripting (XSS) vulnerability in the Build Failure Analyzer plugin before 1.16.0 in Jenkins allows remote attackers to inject arbitrary web script…

medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
Cross-site scripting (XSS) vulnerability in the Build Failure Analyzer plugin before 1.16.0 in Jenkins allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter.

Affected

8 ranges
VendorProductVersion rangeFixed in
jenkinsasync_http_client_plugin
jenkinsbuild_failure_analyzer< 1.16.01.16.0
jenkinsbuild_failure_analyzer_plugin
jenkinsimage_gallery_plugin
jenkinstap_plugin
jenkinsusers_of_build_failure_analyzer_plugin
jenkinsusers_of_image_gallery_plugin
jenkinsusers_of_tap_plugin