Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7f84-p6r5-jr6q

Опубликовано: 24 июн. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8

Описание

Cross-site Scripting vulnerability in Jenkins

Since Jenkins 2.321 and LTS 2.332.1, the HTML output generated for new symbol-based SVG icons includes the title attribute of l:ionicon until Jenkins 2.334 and alt attribute of l:icon since Jenkins 2.335 without further escaping.

This vulnerability is known to be exploitable by attackers with Job/Configure permission.

Jenkins 2.356, LTS 2.332.4 and LTS 2.346.1 addresses this vulnerability, the title attribute of l:ionicon (Jenkins LTS 2.332.4) and alt attribute of l:icon (Jenkins 2.356 and LTS 2.346.1) are escaped in the generated HTML output.

Пакеты

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 2.350, < 2.356

2.356

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

>= 2.346, < 2.346.1

2.346.1

Наименование

org.jenkins-ci.main:jenkins-core

maven
Затронутые версииВерсия исправления

< 2.332.4

2.332.4

EPSS

Процентиль: 89%
0.04332
Низкий

8 High

CVSS3

Дефекты

CWE-22
CWE-79

Связанные уязвимости

CVSS3: 6.1
redhat
больше 3 лет назад

In Jenkins 2.321 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the HTML output generated for new symbol-based SVG icons includes the 'title' attribute of 'l:ionicon' (until Jenkins 2.334) and 'alt' attribute of 'l:icon' (since Jenkins 2.335) without further escaping, resulting in a cross-site scripting (XSS) vulnerability.

CVSS3: 5.4
nvd
больше 3 лет назад

In Jenkins 2.321 through 2.355 (both inclusive) and LTS 2.332.1 through LTS 2.332.3 (both inclusive) the HTML output generated for new symbol-based SVG icons includes the 'title' attribute of 'l:ionicon' (until Jenkins 2.334) and 'alt' attribute of 'l:icon' (since Jenkins 2.335) without further escaping, resulting in a cross-site scripting (XSS) vulnerability.

CVSS3: 5.4
debian
больше 3 лет назад

In Jenkins 2.321 through 2.355 (both inclusive) and LTS 2.332.1 throug ...

EPSS

Процентиль: 89%
0.04332
Низкий

8 High

CVSS3

Дефекты

CWE-22
CWE-79