Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-64r9-x74q-wxmh

Опубликовано: 19 окт. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8

Описание

Stored XSS vulnerability in Jenkins Pipeline: Supporting APIs Plugin

Pipeline: Supporting APIs Plugin provides a feature to add hyperlinks, that send POST requests when clicked, to build logs. These links are used by Pipeline: Input Step Plugin to allow users to proceed or abort the build, or by Pipeline: Job Plugin to allow users to forcibly terminate the build after aborting it.

Pipeline: Supporting APIs Plugin 838.va_3a_087b_4055b and earlier does not sanitize or properly encode URLs of these hyperlinks in build logs.

This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create Pipelines.

Pipeline: Supporting APIs Plugin 839.v35e2736cfd5c properly encodes URLs of these hyperlinks in build logs.

Пакеты

Наименование

org.jenkins-ci.plugins.workflow:workflow-support

maven
Затронутые версииВерсия исправления

< 839.v35e2736cfd5c

839.v35e2736cfd5c

EPSS

Процентиль: 89%
0.04273
Низкий

8 High

CVSS3

Дефекты

CWE-79

Связанные уязвимости

CVSS3: 5.4
redhat
больше 3 лет назад

Jenkins Pipeline: Supporting APIs Plugin 838.va_3a_087b_4055b and earlier does not sanitize or properly encode URLs of hyperlinks sending POST requests in build logs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create Pipelines.

CVSS3: 5.4
nvd
больше 3 лет назад

Jenkins Pipeline: Supporting APIs Plugin 838.va_3a_087b_4055b and earlier does not sanitize or properly encode URLs of hyperlinks sending POST requests in build logs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create Pipelines.

EPSS

Процентиль: 89%
0.04273
Низкий

8 High

CVSS3

Дефекты

CWE-79