An cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.4.1 and earlier in src/main/resources/lib/configfiles/configfiles.jelly that allows attackers with permission to define shared configuration files to execute arbitrary JavaScript when a user attempts to delete the shared configuration file.
CVSS Details
- CVSS 3.1 Base Score: 4.8
- CVSS 3.0 Vector: (CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Redhat Openshift | — | Upgrade openshift-enterprise-autohealUpgrade golang-github-openshift-oauth-proxyUpgrade atomic-openshift-metrics-serverUpgrade atomic-openshift-node-problem-detectorUpgrade openshift-ansibleUpgrade jenkinsUpgrade atomic-openshift-service-idlerUpgrade atomic-openshift-web-consoleUpgrade atomic-openshift-deschedulerUpgrade haproxyUpgrade atomic-openshift-dockerregistryUpgrade golang-github-prometheus-prometheusUpgrade jenkins-2-pluginsUpgrade atomic-openshiftUpgrade golang-github-prometheus-node_exporterUpgrade golang-github-prometheus-alertmanagerUpgrade atomic-openshift-cluster-autoscalerUpgrade atomic-enterprise-service-catalogUpgrade openshift-enterprise-cluster-capacity | Mar 15, 2019 | Jan 28, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub