PT-2023-6025 · Jenkins · Jenkins Fortify Plugin+1
Kevin Guerroudj
·
Publicado
2023-08-21
·
Atualizado
2023-08-24
·
CVE-2023-4303
CVSS v2.0
6.4
Média
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Fortify Plugin versions 22.1.38 and earlier
Description
The issue is related to the failure to protect the web page structure, allowing a remote attacker to perform an HTML injection. This occurs because the error message for a form validation method is not properly escaped, resulting in an HTML injection vulnerability.
Recommendations
For Jenkins Fortify Plugin versions 22.1.38 and earlier, update to version 22.2.39 or later, which removes HTML tags from the error message, thus resolving the issue.
Correção
XSS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Jenkins
Jenkins Fortify Plugin