Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-35144

Опубликовано: 14 июн. 2023
Источник: redhat
CVSS3: 8

Описание

Jenkins Maven Repository Server Plugin 1.10 and earlier does not escape project and build display names on the Build Artifacts As Maven Repository page, resulting in a stored cross-site scripting (XSS) vulnerability.

A flaw was found in the Jenkins Maven Repository Server Plugin, where it is vulnerable to Cross-site scripting caused by the improper validation of user-supplied input. A remote, authenticated attacker could exploit this vulnerability to inject malicious script into a web page, which would be executed in a victim's web browser within the security context of the hosting web site once the page is viewed. This flaw allows an attacker to steal the victim's cookie-based authentication credentials.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 2jenkins-2-pluginsNot affected
Node HealthCheck Operatorjenkins-2-pluginsNot affected
OpenShift Developer Tools and Servicesjenkins-2-pluginsNot affected
Red Hat OpenShift Container Platform 3.11jenkins-2-pluginsNot affected
Red Hat OpenShift Container Platform 4jenkins-2-pluginsNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2215087jenkins-2-plugins: repository: Stored XSS vulnerability in Maven Repository Server Plugin

8 High

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
больше 2 лет назад

Jenkins Maven Repository Server Plugin 1.10 and earlier does not escape project and build display names on the Build Artifacts As Maven Repository page, resulting in a stored cross-site scripting (XSS) vulnerability.

CVSS3: 5.4
github
больше 2 лет назад

Stored XSS vulnerability in Jenkins Maven Repository Server Plugin

8 High

CVSS3