cbcvebase.
CVE-2017-1000102
published 2017-10-05

CVE-2017-1000102: The Details view of some Static Analysis Utilities based plugins, was vulnerable to a persisted cross-site scripting vulnerability: Malicious users able to…

PriorityP423medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
EPSS
0.74%
50.4th percentile
The Details view of some Static Analysis Utilities based plugins, was vulnerable to a persisted cross-site scripting vulnerability: Malicious users able to influence the input to these plugins, for example the console output which is parsed to extract build warnings (Warnings Plugin), could insert arbitrary HTML into this view.

Affected

13 ranges
VendorProductVersion rangeFixed in
jenkinsblue_ocean_plugin
jenkinsconfig_file_provider_plugin
jenkinscredentials_plugin
jenkinsdatadog_plugin
jenkinsdeploy_to_container_plugin
jenkinsdry_plugin
jenkinsgroovy_plugin
jenkinsinput_step_plugin
jenkinsowasp_dependency-check_plugin
jenkinsscript_security_plugin
jenkinsstatic_analysis_utilities<= 1.91
jenkinsstatic_analysis_utilities_plugin
jenkinswarnings_plugin

CVSS provenance

nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.