CVE-2019-1003013

MEDIUM5.4EPSS 0.06%

Cross-site Scripting in Jenkins Blue Ocean Plugin

Published: 5/13/2022Modified: 2/16/2024

Description

A cross-site scripting vulnerability exists in Jenkins Blue Ocean Plugins 1.10.1 and earlier that allows attackers with permission to edit a user's description in Jenkins to have Blue Ocean render arbitrary HTML when using it as that user. This vulnerability is found in: - blueocean-commons/src/main/java/io/jenkins/blueocean/commons/stapler/Export.java - blueocean-commons/src/main/java/io/jenkins/blueocean/commons/stapler/export/ExportConfig.java - blueocean-commons/src/main/java/io/jenkins/blueocean/commons/stapler/export/JSONDataWriter.java - blueocean-rest-impl/src/main/java/io/jenkins/blueocean/service/embedded/UserStatePreloader.java - blueocean-web/src/main/resources/io/jenkins/blueocean/PageStatePreloadDecorator/header.jelly

Affected packages (1)

CVSS scores

SourceVersionSeverityVector
osvCVSS 3.1MEDIUM5.4CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

References (5)