CVE-2013-6374

Jenkins-ci Build Failure Analyzer < 1.5.0 - XSS

Title source: rule

Description

Cross-site scripting (XSS) vulnerability in the Build Failure Analyzer plugin before 1.5.1 for Jenkins allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

Scores

EPSS 0.0020
EPSS Percentile 42.0%

Details

CWE
CWE-79
Status published
Products (6)
jenkins-ci/build_failure_analyzer < 1.5.0
jenkins-ci/build_failure_analyzer
jenkins-ci/build_failure_analyzer
jenkins-ci/build_failure_analyzer
com.sonyericsson.jenkins.plugins.bfa/build-failure-analyzer < 1.5.1Maven
n/a/n/a
Published Nov 25, 2013
Tracked Since Feb 18, 2026