PT-2019-11735 · Jenkins · Jenkins Electricflow Plugin+1

Daniel Beck

·

Published

2019-06-11

·

Updated

2023-10-25

·

CVE-2019-10335

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins ElectricFlow Plugin version 1.1.5 and earlier
Description A stored cross-site scripting issue allows attackers to inject arbitrary HTML and JavaScript in the plugin-provided output on build status pages. This occurs because user content was not properly escaped, enabling users with Job/Configure permission or attackers controlling API responses from ElectricFlow to render arbitrary HTML and JavaScript on Jenkins build pages.
Recommendations For Jenkins ElectricFlow Plugin version 1.1.5 and earlier, update the plugin to a version that includes the security update, which filters build metadata through a HTML formatter and properly escapes content received from ElectricFlow.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2019-10335
GHSA-FX9P-2QVX-PGJV

Affected Products

Jenkins
Jenkins Electricflow Plugin