Multiple cross-site scripting (XSS) vulnerabilities in ZeroClipboard.swf in ZeroClipboard before 1.3.2, as maintained by Jon Rohan and James M. Greene, allow remote attackers to inject arbitrary web script or HTML via vectors related to certain SWF query parameters (aka loaderInfo.parameters).
CVSS Details
- CVSS 3.1 Base Score: 6.1
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | No solution exists | May 15, 2025 | May 15, 2025 |
| Freebsd | — | Upgrade jenkins-ltsUpgrade jenkins | Dec 10, 2025 | Oct 1, 2014 |
| Jenkins 2014 10 01 | — | Upgrade Jenkins to the latest versionUpgrade Jenkins LTS to the latest versionUpgrade Jenkins to version 1.583Upgrade Jenkins LTS to version 1.565.3 | Nov 13, 2017 | Feb 8, 2014 |
| Redhat Openshift | — | Upgrade atomic-openshift | Jun 18, 2018 | Jan 31, 2014 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub