CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 6.1. It affects Jenkins.
CVE
CVE-2018-1000426
Severity
MEDIUM
CVSS
6.1
EPSS
0.99%
Jenkins
Original NVD Description
A cross-site scripting vulnerability exists in Jenkins Git Changelog Plugin 2.6 and earlier in GitChangelogSummaryDecorator/summary.jelly, GitChangelogLeftsideBuildDecorator/badge.jelly, GitLogJiraFilterPostPublisher/config.jelly, GitLogBasicChangelogPostPublisher/config.jelly that allows attackers able to control the Git history parsed by the plugin to have Jenkins render arbitrary HTML on some pages.
Related CVEs
Other vulnerabilities affecting the same vendor(s)