CVE-2018-1000144
Jenkins Cucumber Living Documentation Plugin Cross-site Scripting vulnerability
6.1
MEDIUM
CVSS 3.1
EPSS 0.07%
Description
A cross site scripting vulnerability exists in Jenkins Cucumber Living Documentation Plugin 1.0.12 and older in CukedoctorBaseAction#doDynamic that disables the Content-Security-Policy protection for archived artifacts and workspace files, allowing attackers able to control the content of these files to attack Jenkins users. This has been addressed in version 1.1.0 of the plugin, and it will now request that users change the Content-Security-Policy option in Jenkins.
How to fix CVE-2018-1000144
To remediate CVE-2018-1000144, upgrade the affected package to a fixed version below.
- —upgrade to 1.1.0 or later
Is CVE-2018-1000144 being exploited?
Low — EPSS is 0.1%, meaning exploitation activity has not been observed at scale.
Affected packages (1)
- from 0, < 1.1.0
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM6.1 | CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N |