Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7rrj-hqv6-fvpp

Опубликовано: 19 окт. 2022
Источник: github
Github: Прошло ревью
CVSS3: 8

Описание

Content-Security-Policy protection for user content can be disabled in Jenkins 360 FireLine Plugin

Jenkins sets the Content-Security-Policy header to static files served by Jenkins (specifically DirectoryBrowserSupport), such as workspaces, /userContent, or archived artifacts, unless a Resource Root URL is specified.

360 FireLine Plugin 1.7.2 and earlier globally disables the Content-Security-Policy header for static files served by Jenkins whenever the 'Execute FireLine' build step is executed, if the option 'Open access to HTML with JS or CSS' is checked. This allows cross-site scripting (XSS) attacks by users with the ability to control files in workspaces, archived artifacts, etc.

Jenkins instances with Resource Root URL configured are unaffected.

Пакеты

Наименование

org.jenkins-ci.plugins.plugin:fireline

maven
Затронутые версииВерсия исправления

<= 1.7.2

Отсутствует

EPSS

Процентиль: 79%
0.01301
Низкий

8 High

CVSS3

Дефекты

CWE-693

Связанные уязвимости

CVSS3: 5.3
nvd
больше 3 лет назад

Jenkins 360 FireLine Plugin 1.7.2 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download.

EPSS

Процентиль: 79%
0.01301
Низкий

8 High

CVSS3

Дефекты

CWE-693