Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2023-39151

Опубликовано: 26 июл. 2023
Источник: redhat
CVSS3: 8
EPSS Низкий

Описание

Jenkins 2.415 and earlier, LTS 2.401.2 and earlier does not sanitize or properly encode URLs in build logs when transforming them into hyperlinks, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control build log contents.

A flaw was found in Jenkins, where Jenkins weekly and LTS are vulnerable to Cross-site scripting caused by the improper validation of user-supplied input. A remote, authenticated attacker can inject malicious script into a web page, which would be executed in a victim's Web browser within the security context of the hosting Web site once the page is viewed. This flaw allows an attacker to steal the victim's cookie-based authentication credentials.

Отчет

OpenShift 3.11 is already in the ELS support model phase. The Jenkins components are out of scope of the ELS support; hence OpenShift 3.11 Jenkins component is marked in this CVE as out of support scope.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and ServicesjenkinsAffected
Red Hat OpenShift Container Platform 3.11jenkinsOut of support scope
Red Hat OpenShift Container Platform 4jenkinsAffected

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2226895jenkins: Stored cross-site scripting via build logs

EPSS

Процентиль: 77%
0.01057
Низкий

8 High

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
больше 2 лет назад

Jenkins 2.415 and earlier, LTS 2.401.2 and earlier does not sanitize or properly encode URLs in build logs when transforming them into hyperlinks, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control build log contents.

CVSS3: 5.4
debian
больше 2 лет назад

Jenkins 2.415 and earlier, LTS 2.401.2 and earlier does not sanitize o ...

CVSS3: 8
github
больше 2 лет назад

Jenkins Stored Cross-site Scripting vulnerability

EPSS

Процентиль: 77%
0.01057
Низкий

8 High

CVSS3