CVE-2014-3678

Cross-site scripting (XSS) vulnerability in the Monitoring plugin before 1.53.0 for Jenkins allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Cross-site Scripting
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
4.3 UNKNOWN
NETWORK
MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
redhatCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 48%
VendorProductVersion
jenkins-cimonitoring_plugin
𝑥
≤ 1.52.1
jenkins-cimonitoring_plugin
1.40.0
jenkins-cimonitoring_plugin
1.41.0
jenkins-cimonitoring_plugin
1.42.0
jenkins-cimonitoring_plugin
1.43.0
jenkins-cimonitoring_plugin
1.44.0
jenkins-cimonitoring_plugin
1.45.0
jenkins-cimonitoring_plugin
1.46.0
jenkins-cimonitoring_plugin
1.47.0
jenkins-cimonitoring_plugin
1.48.0
jenkins-cimonitoring_plugin
1.49.0
jenkins-cimonitoring_plugin
1.50.0
jenkins-cimonitoring_plugin
1.51.0
jenkins-cimonitoring_plugin
1.52.0
𝑥
= Vulnerable software versions