PT-2019-11735 · Jenkins · Jenkins Electricflow Plugin+1
Daniel Beck
·
Published
2019-06-11
·
Updated
2023-10-25
·
CVE-2019-10335
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins ElectricFlow Plugin version 1.1.5 and earlier
Description
A stored cross-site scripting issue allows attackers to inject arbitrary HTML and JavaScript in the plugin-provided output on build status pages. This occurs because user content was not properly escaped, enabling users with Job/Configure permission or attackers controlling API responses from ElectricFlow to render arbitrary HTML and JavaScript on Jenkins build pages.
Recommendations
For Jenkins ElectricFlow Plugin version 1.1.5 and earlier, update the plugin to a version that includes the security update, which filters build metadata through a HTML formatter and properly escapes content received from ElectricFlow.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Electricflow Plugin