PT-2019-11735 · Jenkins · Jenkins Electricflow Plugin+1

·

CVE-2019-10335

·

Publicado

2019-06-11

·

Atualizado

2023-10-25

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins ElectricFlow Plugin version 1.1.5 and earlier
Description A stored cross-site scripting issue allows attackers to inject arbitrary HTML and JavaScript in the plugin-provided output on build status pages. This occurs because user content was not properly escaped, enabling users with Job/Configure permission or attackers controlling API responses from ElectricFlow to render arbitrary HTML and JavaScript on Jenkins build pages.
Recommendations For Jenkins ElectricFlow Plugin version 1.1.5 and earlier, update the plugin to a version that includes the security update, which filters build metadata through a HTML formatter and properly escapes content received from ElectricFlow.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-10335
GHSA-FX9P-2QVX-PGJV

Produtos afetados

Jenkins
Jenkins Electricflow Plugin