V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2013-2033
DEB
Medium

Cross-site scripting (XSS) vulnerability in Jenkins before 1.514, LTS before 1.509.1, and Enterprise 1.466.x before 1.466.14.1 and 1.480.x …

CVSS
4.3
Medium
EPSS
0.02
p76
Published
2013-01-01
Updated
2013-01-01
Description

Cross-site scripting (XSS) vulnerability in Jenkins before 1.514, LTS before 1.509.1, and Enterprise 1.466.x before 1.466.14.1 and 1.480.x before 1.480.4.1 allows remote authenticated users with write permission to inject arbitrary web script or HTML via unspecified vectors.

Tags · CWE
XSS
CWE-79
CAPEC-63
CAPEC-85
CAPEC-209
CAPEC-588
CAPEC-591
CAPEC-592
Affected products
ImagemagickAtlasFacterGdGdbmGeosGhostscriptHaproxyJasperJboss-eap6-indexJboss-eap6-modulesJenkinsJenkinsJenkins-plugin-openshiftJsLapackLcmsLibc-clientLibcgroupLibmcrypt
CVSS vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Timeline
2013-01-01
Published
2013-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: M
Medium
Authentication
Au: N
None (N)
Confidentiality Impact
C: N
None (N)
Integrity Impact
I: P
Partial
Availability Impact
A: N
None (N)
Exploit indicators
EPSS
0.019 · p76
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
ImageMagickTracked
atlasTracked
facterTracked
gdTracked
gdbmTracked
geosTracked
ghostscriptTracked
haproxyTracked
jasperTracked
jboss-eap6-indexTracked
jboss-eap6-modulesTracked
jenkinsTracked
jenkinsTracked
jenkins-plugin-openshiftTracked
jsTracked
lapackTracked
lcmsTracked
libc-clientTracked
libcgroupTracked
libmcryptTracked
Showing first 20 of 133
Source databases
DEB
CVE
RED