Описание
Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not escape the user-provided description of a generic offline cause that could be set through the POST config.xml API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.
A flaw was found in Jenkins. This vulnerability, a stored cross-site scripting (XSS) issue, allows attackers with Agent/Configure permission to inject malicious scripts into the user-provided description of a generic offline cause. When other users view this description, the injected script can execute in their browser, potentially leading to information disclosure or unauthorized actions.
Меры по смягчению последствий
To fully mitigate this vulnerability, upgrade the Jenkins instance to version 2.568 or LTS 2.555.3 (or later). These releases officially resolve the issue by securely rendering the offline cause descriptions as plain text. If an immediate upgrade is not feasible, the risk can be significantly reduced by auditing Role-Based Access Control (RBAC) settings and strictly limiting the Agent/Configure permission to highly trusted, essential administrators only.
Затронутые пакеты
| Платформа | Пакет | Состояние | Рекомендация | Релиз |
|---|---|---|---|---|
| OpenShift Developer Tools and Services | jenkins | Fix deferred |
Показывать по
Дополнительная информация
Статус:
5.4 Medium
CVSS3
Связанные уязвимости
Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not escape the user-provided description of a generic offline cause that could be set through the `POST config.xml` API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.
Jenkins: Stored XSS vulnerability in node offline cause description
5.4 Medium
CVSS3