PT-2023-8996 · Jenkins+1 · Jenkins+1

Yaroslav Afenkin

·

Publicado

2023-09-20

·

Atualizado

2024-04-11

·

CVE-2023-43495

CVSS v3.1

8.0

Alta

VetorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins versions 2.423 and earlier, LTS versions 2.414.1 and earlier
Description The issue is related to the lack of escaping of the caption constructor parameter value of ExpandableDetailsNote, resulting in a stored cross-site scripting (XSS) vulnerability. This vulnerability can be exploited by attackers who can control this parameter, potentially allowing them to manage files in workspaces. The ExpandableDetailsNote feature allows annotating build log content with additional information that can be revealed when interacted with.
Recommendations For Jenkins versions 2.423 and earlier, update to version 2.424 or later. For LTS versions 2.414.1 and earlier, update to version 2.414.2 or later. As a temporary workaround, consider restricting access to the ExpandableDetailsNote feature until a patch is available. Avoid using the caption parameter in the affected ExpandableDetailsNote constructor until the issue is resolved.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-02900
BIT-JENKINS-2023-43495
CVE-2023-43495
GHSA-5J46-5HWQ-GWH7

Produtos afetados

Jenkins
Red Os