Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2022-43409

Опубликовано: 19 окт. 2022
Источник: redhat
CVSS3: 5.4
EPSS Низкий

Описание

Jenkins Pipeline: Supporting APIs Plugin 838.va_3a_087b_4055b and earlier does not sanitize or properly encode URLs of hyperlinks sending POST requests in build logs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create Pipelines.

A Cross-site scripting (XSS) vulnerability was found in a Jenkins plugin. This issue may allow an authenticated remote attacker to create Pipelines.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.11jenkins-2-pluginsOut of support scope
OCP-Tools-4.12-RHEL-8jenkins-2-pluginsFixedRHSA-2023:106406.03.2023
OpenShift Developer Tools and Services for OCP 4.11jenkins-2-pluginsFixedRHSA-2023:319817.05.2023
Red Hat OpenShift Container Platform 4.10jenkins-2-pluginsFixedRHSA-2023:056008.02.2023
Red Hat OpenShift Container Platform 4.9jenkins-2-pluginsFixedRHSA-2023:077723.02.2023

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2136391jenkins-plugin/workflow-support: Stored XSS vulnerability in Pipeline: Supporting APIs Plugin

EPSS

Процентиль: 89%
0.04273
Низкий

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
больше 3 лет назад

Jenkins Pipeline: Supporting APIs Plugin 838.va_3a_087b_4055b and earlier does not sanitize or properly encode URLs of hyperlinks sending POST requests in build logs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create Pipelines.

CVSS3: 8
github
больше 3 лет назад

Stored XSS vulnerability in Jenkins Pipeline: Supporting APIs Plugin

EPSS

Процентиль: 89%
0.04273
Низкий

5.4 Medium

CVSS3