CVE-2013-6374
Jenkins-ci Build Failure Analyzer < 1.5.0 - XSS
Title source: ruleDescription
Cross-site scripting (XSS) vulnerability in the Build Failure Analyzer plugin before 1.5.1 for Jenkins allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
References (4)
Scores
EPSS
0.0020
EPSS Percentile
42.0%
Details
CWE
CWE-79
Status
published
Products (6)
jenkins-ci/build_failure_analyzer
< 1.5.0
jenkins-ci/build_failure_analyzer
jenkins-ci/build_failure_analyzer
jenkins-ci/build_failure_analyzer
com.sonyericsson.jenkins.plugins.bfa/build-failure-analyzer
< 1.5.1Maven
n/a/n/a
Published
Nov 25, 2013
Tracked Since
Feb 18, 2026