An cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.4.1 and earlier in src/main/resources/lib/configfiles/configfiles.jelly that allows attackers with permission to define shared configuration files to execute arbitrary JavaScript when a user attempts to delete the shared configuration file.
CVSS Details
- CVSS 3.1 Base Score: 4.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat Openshift | — | Upgrade openshift-enterprise-autohealUpgrade openshift-ansibleUpgrade atomic-openshift-service-idlerUpgrade atomic-openshift-web-consoleUpgrade atomic-openshift-metrics-serverUpgrade golang-github-openshift-oauth-proxyUpgrade jenkinsUpgrade atomic-openshift-node-problem-detectorUpgrade atomic-openshift-deschedulerUpgrade jenkins-2-pluginsUpgrade atomic-openshift-cluster-autoscalerUpgrade atomic-enterprise-service-catalogUpgrade atomic-openshiftUpgrade golang-github-prometheus-node_exporterUpgrade openshift-enterprise-cluster-capacityUpgrade atomic-openshift-dockerregistryUpgrade haproxyUpgrade golang-github-prometheus-prometheusUpgrade golang-github-prometheus-alertmanager | Mar 15, 2019 | Jan 28, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub