First published: Thu Mar 28 2019(Updated: )
A cross site scripting vulnerability in Jenkins Lockable Resources Plugin 2.4 and earlier allows attackers able to control resource names to inject arbitrary JavaScript in web pages rendered by the plugin.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
redhat/jenkins-plugin-lockable-resources | <2.5 | 2.5 |
Jenkins Lockable Resources | <=2.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-1003042 has been classified as a medium severity vulnerability due to its potential impact on web application security through cross site scripting.
To remediate CVE-2019-1003042, upgrade the Jenkins Lockable Resources Plugin to version 2.5 or later.
CVE-2019-1003042 is caused by the improper escaping of resource names which allows injection of arbitrary JavaScript in web pages.
Versions 2.4 and earlier of Jenkins Lockable Resources Plugin are affected by CVE-2019-1003042.
Yes, CVE-2019-1003042 can be exploited remotely by attackers able to control resource names in Jenkins.