Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-32977

Опубликовано: 16 мая 2023
Источник: redhat
CVSS3: 7.5
EPSS Низкий

Описание

Jenkins Pipeline: Job Plugin does not escape the display name of the build that caused an earlier build to be aborted, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to set build display names immediately.

A flaw was found in the Jenkins Pipeline: Job Plugin. Affected versions of Jenkins Pipeline: Job Plugin are vulnerable to Cross-site scripting caused by improper validation of user-supplied input. This flaw allows a remote authenticated attacker to inject malicious script into a Web page, which would then be executed in a victim's Web browser within the security context of the hosting Web site once the page is viewed. The attacker could use this vulnerability to steal the victim's cookie-based authentication credentials.

Отчет

OpenShift 3.11 is in ELS. Jenkins and its related technologies will not be supported under ELS. Hence, OpenShift 3.11 is marked as affected/won'tfix.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat OpenShift Container Platform 3.11jenkins-2-pluginsWill not fix
OCP-Tools-4.12-RHEL-8jenkins-2-pluginsFixedRHSA-2023:361015.06.2023
OpenShift Developer Tools and Services for OCP 4.11jenkins-2-pluginsFixedRHSA-2023:366319.06.2023
Red Hat OpenShift Container Platform 4.10jenkins-2-pluginsFixedRHSA-2023:362523.06.2023

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2207830jenkins-2-plugin: workflow-job: Stored XSS vulnerability in Pipeline: Job Plugin

EPSS

Процентиль: 86%
0.02963
Низкий

7.5 High

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
больше 2 лет назад

Jenkins Pipeline: Job Plugin does not escape the display name of the build that caused an earlier build to be aborted, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to set build display names immediately.

CVSS3: 7.5
github
больше 2 лет назад

Jenkins Pipeline: Job Plugin vulnerable to stored Cross-site Scripting

EPSS

Процентиль: 86%
0.02963
Низкий

7.5 High

CVSS3