Описание
An cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.4.1 and earlier in src/main/resources/lib/configfiles/configfiles.jelly that allows attackers with permission to define shared configuration files to execute arbitrary JavaScript when a user attempts to delete the shared configuration file.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Container Platform 3.10 | jenkins-plugin-config-file-provider | Will not fix | ||
| Red Hat OpenShift Container Platform 3.6 | jenkins-plugin-config-file-provider | Will not fix | ||
| Red Hat OpenShift Container Platform 3.7 | jenkins-plugin-config-file-provider | Will not fix | ||
| Red Hat OpenShift Container Platform 3.9 | jenkins-plugin-config-file-provider | Will not fix | ||
| Red Hat OpenShift Container Platform 4 | jenkins-2-plugins | Affected | ||
| Red Hat OpenShift Container Platform 3.11 | atomic-enterprise-service-catalog | Fixed | RHBA-2019:0326 | 20.02.2019 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift | Fixed | RHBA-2019:0326 | 20.02.2019 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-cluster-autoscaler | Fixed | RHBA-2019:0326 | 20.02.2019 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-descheduler | Fixed | RHBA-2019:0326 | 20.02.2019 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-dockerregistry | Fixed | RHBA-2019:0326 | 20.02.2019 |
Показывать по
Дополнительная информация
Статус:
EPSS
4.8 Medium
CVSS3
Связанные уязвимости
An cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.4.1 and earlier in src/main/resources/lib/configfiles/configfiles.jelly that allows attackers with permission to define shared configuration files to execute arbitrary JavaScript when a user attempts to delete the shared configuration file.
Jenkins Config File Provider Plugin XSS vulnerability
EPSS
4.8 Medium
CVSS3