PT-2018-5186 · Jenkins · Jenkins Delivery Pipeline Plugin+1
Viktor Gazdag
·
Publicado
2018-01-26
·
Atualizado
2022-05-14
·
CVE-2017-1000404
CVSS v3.1
6.1
Média
| Vetor | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Delivery Pipeline Plugin versions 1.0.7 and earlier
Description
The issue arises from the unescaped content of the query parameter
fullscreen in the plugin's JavaScript, leading to a cross-site scripting vulnerability through specially crafted URLs.Recommendations
For Jenkins Delivery Pipeline Plugin versions 1.0.7 and earlier, update to version 1.0.8 or later, which converts the
fullscreen parameter value to a boolean (true/false) and inserts that into the page instead, mitigating the cross-site scripting vulnerability.Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Jenkins
Jenkins Delivery Pipeline Plugin