Lucene search

K
osvGoogleOSV:GHSA-262F-77Q5-RQV6
HistorySep 20, 2023 - 6:30 p.m.

Jenkins Build Failure Analyzer Plugin Cross-site Scripting vulnerability

2023-09-2018:30:21
Google
osv.dev
9
jenkins
build failure analyzer
cross-site scripting
vulnerability
software.

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

33.0%

Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier does not escape Failure Cause names in build logs.

This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create or update Failure Causes.

Build Failure Analyzer Plugin 2.4.2 escapes Failure Cause names in build logs.

CVSS3

5.4

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

EPSS

0.001

Percentile

33.0%