-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:jobConfigHistory | maven | <= 1165.v8cc9fd1f4597 | 1166.vc9f255f45b |
The analysis focuses on the changes made in the patch to understand how the vulnerability is mitigated. The 'removeEntryFromTable' function is identified as a key point of interest because it's where the potentially malicious input (job name) is used. The patch changes how this input is handled, indicating that the original handling was vulnerable to XSS.
Ongoing coverage of React2Shell