Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2019-1003050

Опубликовано: 10 апр. 2019
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

The f:validateButton form control for the Jenkins UI did not properly escape job URLs in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, resulting in a cross-site scripting (XSS) vulnerability exploitable by users with the ability to control job names.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.10jenkinsWill not fix
Red Hat OpenShift Container Platform 3.4jenkinsOut of support scope
Red Hat OpenShift Container Platform 3.5jenkinsOut of support scope
Red Hat OpenShift Container Platform 3.6jenkinsWill not fix
Red Hat OpenShift Container Platform 3.7jenkinsWill not fix
Red Hat OpenShift Container Platform 3.9jenkinsWill not fix
Red Hat OpenShift Container Platform 4jenkinsNot affected
Red Hat OpenShift Container Platform 3.11atomic-enterprise-service-catalogFixedRHBA-2019:160526.06.2019
Red Hat OpenShift Container Platform 3.11atomic-openshift-cluster-autoscalerFixedRHBA-2019:160526.06.2019
Red Hat OpenShift Container Platform 3.11atomic-openshift-deschedulerFixedRHBA-2019:160526.06.2019

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=1699333jenkins: Improper escaping of job URLs in f:validateButton leads to cross-site scripting vulnerability.

EPSS

Процентиль: 76%
0.00967
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
почти 7 лет назад

The f:validateButton form control for the Jenkins UI did not properly escape job URLs in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, resulting in a cross-site scripting (XSS) vulnerability exploitable by users with the ability to control job names.

CVSS3: 5.4
debian
почти 7 лет назад

The f:validateButton form control for the Jenkins UI did not properly ...

CVSS3: 5.4
github
больше 3 лет назад

Improper Neutralization of Input During Web Page Generation in Jenkins

EPSS

Процентиль: 76%
0.00967
Низкий

5.4 Medium

CVSS3