PT-2020-15383 · Jenkins · Jenkins Gatling Plugin+1
Daniel Beck
·
Published
2020-04-07
·
Updated
2023-11-02
·
CVE-2020-2173
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Gatling Plugin versions 1.2.7 and earlier
Description
The issue results in a cross-site scripting (XSS) vulnerability, which is exploitable by users able to change report content. This occurs because the plugin prevents Content-Security-Policy headers from being set for Gatling reports, effectively bypassing the Content-Security-Policy protection introduced in certain Jenkins versions.
Recommendations
For versions 1.2.7 and earlier, consider updating to version 1.3.0 or later, which no longer allows viewing Gatling reports directly in Jenkins, thereby mitigating the risk of exploitation. As a temporary workaround, consider restricting access to the Gatling reports served by the plugin until a patch is available.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Gatling Plugin