CVE-2016-4988
medium
CVSS v3
6.1
CVSS v2
4.3
VIR risk
6.1
Description
Cross-site Scripting in Jenkins Build Failure Analyzer plugin
Predictions
Exploit likelihood
71%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: nvd@nist.gov — https://jenkins.io/security/advisory/2016-06-20/
Vendor advisory: secalert@redhat.com — https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2016-06-20
Package impact
| Ecosystem | Package | Vulnerable | Fixed |
|---|---|---|---|
| Maven | com.sonyericsson.jenkins.plugins.bfa:build-failure-analyzer | <1.16.0 | 1.16.0 |
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| jenkins | build_failure_analyzer | {"endExcluding":"1.16.0"} | 1.16.0 |
References
CWEs
CWE-79
Verify integrity in audit chain (admin only). AS-IS.