CVE-2018-1000413
Description
A cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.1 and earlier in configfiles.jelly, providerlist.jelly that allows users with the ability to configure configuration files to insert arbitrary HTML into some pages in Jenkins.
- CVSS Version 3.1
- CVSS Version 2.0
nvd
CVE ID: CVE-2018-1000413
Base Score: 5.4
Base Severity: MEDIUM
Vector String:CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Impact Score: 2.7
Exploitability Score: 2.3
nvd
CVE ID: CVE-2018-1000413
Base Score: 3.5
Base Severity: LOW
Vector String:AV:N/AC:M/Au:S/C:N/I:P/A:N
Refrence: NVD