Описание
Jenkins HTML Publisher Plugin 1.16 through 1.32 (both inclusive) does not properly sanitize input, allowing attackers with Item/Configure permission to implement cross-site scripting (XSS) attacks and to determine whether a path on the Jenkins controller file system exists.
A flaw was found in jenkins-2-plugins. In the HTML Publisher Plugin 1.16 through 1.32, fallback for reports created in HTML Publisher Plugin 1.15 and earlier does not properly sanitize input. This can allow attackers with Item/Configure permissions to implement stored cross-site scripting (XSS) attacks and determine whether a path on the Jenkins controller file system exists, without being able to access it.
Отчет
HTML Publisher Plugin 1.32.1 removes support for reports created before HTML Publisher Plugin 1.15. Those reports are retained on the disk, but may no longer be accessible through the Jenkins UI.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| Red Hat OpenShift Container Platform 3.11 | jenkins-2-plugins | Out of support scope | ||
| OCP-Tools-4.12-RHEL-8 | jenkins | Fixed | RHSA-2024:3635 | 05.06.2024 |
| OCP-Tools-4.12-RHEL-8 | jenkins-2-plugins | Fixed | RHSA-2024:3635 | 05.06.2024 |
| OCP-Tools-4.13-RHEL-8 | jenkins | Fixed | RHSA-2024:3636 | 05.06.2024 |
| OCP-Tools-4.13-RHEL-8 | jenkins-2-plugins | Fixed | RHSA-2024:3636 | 05.06.2024 |
| OCP-Tools-4.14-RHEL-8 | jenkins | Fixed | RHSA-2024:3634 | 05.06.2024 |
| OCP-Tools-4.14-RHEL-8 | jenkins-2-plugins | Fixed | RHSA-2024:3634 | 05.06.2024 |
| OCP-Tools-4.15-RHEL-8 | jenkins | Fixed | RHSA-2024:4597 | 17.07.2024 |
| OCP-Tools-4.15-RHEL-8 | jenkins-2-plugins | Fixed | RHSA-2024:4597 | 17.07.2024 |
Показывать по
Дополнительная информация
Статус:
EPSS
8 High
CVSS3
Связанные уязвимости
Jenkins HTML Publisher Plugin 1.16 through 1.32 (both inclusive) does not properly sanitize input, allowing attackers with Item/Configure permission to implement cross-site scripting (XSS) attacks and to determine whether a path on the Jenkins controller file system exists.
Jenkins HTML Publisher Plugin does not properly sanitize input
Уязвимость плагина Jenkins HTML Publisher, существующая из-за непринятия мер по защите структуры веб-страницы, позволяющая нарушителю проводить межсайтовые сценарные атаки и определять, существует ли путь к файловой системе контроллера Jenkins
EPSS
8 High
CVSS3