First published: Tue Mar 13 2018(Updated: )
A cross-site scripting vulnerability exists in Jenkins TestLink Plugin 2.12 and earlier in TestLinkBuildAction/summary.jelly and others that allow an attacker who can control e.g. TestLink report names to have Jenkins serve arbitrary HTML and JavaScript
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
maven/org.jenkins-ci.plugins:testlink | <=2.12 | 2.13 |
Jenkins Testlink | <=3.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-1000113 is medium.
CVE-2018-1000113 allows an attacker who can control TestLink report names to have Jenkins serve arbitrary HTML and JavaScript.
Jenkins TestLink Plugin versions 2.12 and earlier are affected by CVE-2018-1000113.
An attacker who can control TestLink report names can use CVE-2018-1000113 to serve arbitrary HTML and JavaScript on Jenkins.
To fix CVE-2018-1000113, upgrade Jenkins TestLink Plugin to version 3.12 or later.