First published: Wed Oct 19 2022(Updated: )
Jenkins 360 FireLine Plugin 1.7.2 and earlier programmatically disables Content-Security-Policy protection for user-generated content in workspaces, archived artifacts, etc. that Jenkins offers for download.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins 360 Fireline | <=1.7.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-43435 has been rated as a medium severity vulnerability due to its potential impact on Content-Security-Policy protection.
To fix CVE-2022-43435, upgrade the Jenkins 360 FireLine Plugin to version 1.7.3 or later.
CVE-2022-43435 affects Jenkins 360 FireLine Plugin versions 1.7.2 and earlier.
The impact of CVE-2022-43435 allows for the potential execution of malicious scripts due to disabled Content-Security-Policy protection.
There is no official workaround for CVE-2022-43435, so updating to a secure version is recommended.