First published: Wed Jan 09 2019(Updated: )
A cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.1 and earlier in configfiles.jelly, providerlist.jelly that allows users with the ability to configure configuration files to insert arbitrary HTML into some pages in Jenkins.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Config File Provider | <=3.1 | |
maven/org.jenkins-ci.plugins:config-file-provider | <=3.1 | 3.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1000413 is a cross-site scripting vulnerability that exists in Jenkins Config File Provider Plugin 3.1 and earlier.
The severity level of CVE-2018-1000413 is medium, with a CVSS score of 5.4.
The cross-site scripting vulnerability in Jenkins Config File Provider Plugin can be exploited by users with the ability to configure configuration files to insert arbitrary HTML into some pages in Jenkins.
CVE-2018-1000413 affects Jenkins Config File Provider Plugin version 3.1 and earlier.
To fix CVE-2018-1000413, it is recommended to upgrade Jenkins Config File Provider Plugin to a version later than 3.1.