CVE-2013-6374

low
Published 2013-11-25 · Modified 2025-03-13
CVSS v3
CVSS v2
3.5
VIR risk
3.5

Description

Jenkins Build Failure Analyzer Plugin allows Cross-Site Scripting (XSS)

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2013-11-20

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://secunia.com/advisories/55783

Package impact

EcosystemPackageVulnerableFixed
java Mavencom.sonyericsson.jenkins.plugins.bfa:build-failure-analyzer<1.5.11.5.1

Application impact

VendorProductVersionsFixed
jenkins-cibuild_failure_analyzer{"endIncluding":"1.5.0"}
jenkins-cibuild_failure_analyzer1.2.0
jenkins-cibuild_failure_analyzer1.3.0
jenkins-cibuild_failure_analyzer1.4.0

References

CWEs

CWE-79

Verify integrity in audit chain (admin only). AS-IS.