Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-35145

Опубликовано: 14 июн. 2023
Источник: redhat
CVSS3: 8

Описание

Jenkins Sonargraph Integration Plugin 5.0.1 and earlier does not escape the file path and the project name for the Log file field form validation, resulting in a stored cross-site scripting vulnerability exploitable by attackers with Item/Configure permission.

A flaw was found in the Jenkins Sonargraph Integration Plugin, where it is vulnerable to Cross-site scripting caused by the improper validation of user-supplied input. This flaw allows a remote, authenticated attacker to inject malicious script into a Web page, which would be executed in a victim's Web browser within the security context of the hosting Web site once the page is viewed, and steal the victim's cookie-based authentication credentials.

Отчет

The Jenkins Sonargraph Integration Plugin is not shipped in any of the Red Hat products. Hence, Red Hat Products are not affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 2jenkins-2-pluginsNot affected
Node HealthCheck Operatorjenkins-2-pluginsNot affected
OpenShift Developer Tools and Servicesjenkins-2-pluginsNot affected
Red Hat OpenShift Container Platform 3.11jenkins-2-pluginsNot affected
Red Hat OpenShift Container Platform 4jenkins-2-pluginsNot affected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2215088jenkins-2-plugins: sonargraph-integration: Stored XSS vulnerability in Sonargraph Integration Plugin

8 High

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
больше 2 лет назад

Jenkins Sonargraph Integration Plugin 5.0.1 and earlier does not escape the file path and the project name for the Log file field form validation, resulting in a stored cross-site scripting vulnerability exploitable by attackers with Item/Configure permission.

CVSS3: 8
github
больше 2 лет назад

Jenkins Sonargraph Integration Plugin vulnerable to Stored Cross-site Scripting

8 High

CVSS3