PT-2023-25165 · Jenkins · Jenkins Template Workflows Plugin+1

Alvaro Muñoz

+1

·

Publicado

2023-06-14

·

Atualizado

2023-06-23

·

CVE-2023-35146

CVSS v3.1

8.0

Alta

VetorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins Template Workflows Plugin versions 41.v32d86a 313b 4a and earlier
Description The issue results in a stored cross-site scripting (XSS) vulnerability. This occurs because the plugin does not escape names of jobs used as building blocks for Template Workflow Job. Attackers who can create jobs may exploit this vulnerability.
Recommendations For Jenkins Template Workflows Plugin versions 41.v32d86a 313b 4a and earlier, consider disabling the Template Workflow Job feature until a patch is available to prevent exploitation of the stored cross-site scripting vulnerability. Restrict access to job creation to minimize the risk of exploitation.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-35146
GHSA-62V2-XWH3-5GVX

Produtos afetados

Jenkins
Jenkins Template Workflows Plugin