MEDIUM
jenkins: Persisted XSS vulnerability in autocompletion suggestions
Published Jan 26, 2018
4.8
MEDIUMCVSS 3.0
EPSS 1.13%
Description
Jenkins 2.88 and earlier; 2.73.2 and earlier Autocompletion suggestions for text fields were not escaped, resulting in a persisted cross-site scripting vulnerability if the source for the suggestions allowed specifying text that includes HTML metacharacters like less-than and greater-than characters.
Affected products
Remediation
No remediation recorded yet.
Weaknesses (1)
References (9)
- http://www.securityfocus.com/bid/101773 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securityfocus.com/bid/102826 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2017-1000392 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1516791 Issue Tracking
- https://github.com/advisories/GHSA-5ppx-rgw2-xg23 Advisory
- https://github.com/jenkinsci/jenkins/commit/f67068170b55633571e5462e52b6124b23d7cb84
- https://jenkins.io/security/advisory/2017-11-08/ x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2017-1000392
- https://www.cve.org/CVERecord?id=CVE-2017-1000392
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/101773 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| http://www.securityfocus.com/bid/102826 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/security/cve/CVE-2017-1000392 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1516791 | Issue Tracking | |
| https://github.com/advisories/GHSA-5ppx-rgw2-xg23 | Advisory | |
| https://github.com/jenkinsci/jenkins/commit/f67068170b55633571e5462e52b6124b23d7cb84 | ||
| https://jenkins.io/security/advisory/2017-11-08/ | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2017-1000392 | ||
| https://www.cve.org/CVERecord?id=CVE-2017-1000392 |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jan 26, 2018
Updated Aug 5, 2024
Reserved Nov 29, 2017
Link CVE-2017-1000392
CISA Vulnrichment
GHSA-5PPX-RGW2-XG23 Updated n/a