PT-2023-21898 · Jenkins · Jenkins Mashup Portlets Plugin+1

·

CVE-2023-28679

·

Publicado

2023-03-23

·

Atualizado

2023-04-08

CVSS v3.1

5.4

Média

VetorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Mashup Portlets Plugin versions 1.1.2 and earlier
Description The issue is related to the "Generic JS Portlet" feature, which allows users to populate a portlet using a custom JavaScript expression. This results in a stored cross-site scripting (XSS) vulnerability that can be exploited by authenticated attackers with Overall/Read permission.
Recommendations For Jenkins Mashup Portlets Plugin versions 1.1.2 and earlier, consider disabling the "Generic JS Portlet" feature until a patch is available to prevent exploitation of the stored cross-site scripting vulnerability.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-28679
GHSA-H9H3-JX58-6HQQ

Produtos afetados

Jenkins
Jenkins Mashup Portlets Plugin