PT-2019-11736 · Cloudbees+1 · Cloudbees Cd Plugin+2
Daniel Beck
·
Published
2019-06-11
·
Updated
2023-10-25
·
CVE-2019-10336
CVSS v3.1
4.7
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins ElectricFlow Plugin version 1.1.6 and earlier
CloudBees CD Plugin (affected versions not specified)
Description
A reflected cross-site scripting issue allows attackers to inject arbitrary HTML and JavaScript into job configuration forms containing post-build steps provided by the plugin. This occurs when attackers can control the output of connected ElectricFlow servers' APIs. The issue affects the configuration forms of various post-build steps contributed by the CloudBees CD Plugin.
Recommendations
For Jenkins ElectricFlow Plugin version 1.1.6 and earlier, update to a version that no longer interprets HTML/JavaScript in responses from ElectricFlow server APIs on job configuration forms.
For CloudBees CD Plugin, ensure the plugin no longer interprets HTML/JavaScript in responses from ElectricFlow server APIs on job configuration forms to prevent exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Cloudbees Cd Plugin
Jenkins
Jenkins Electricflow Plugin