jenkins: Reflected XSS vulnerability
Published Jan 9, 2019
6.5
MEDIUMCVSS 3.0
EPSS 1.53%
Description
A cross-site scripting vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/model/Api.java that allows attackers to specify URLs to Jenkins that result in rendering arbitrary attacker-controlled HTML by Jenkins.
Affected products
No data.
No data.
Red Hat OpenShift Container Platform 3.11
atomic-enterprise-service-catalog-1:3.11.51-1.git.1671.2d16650.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
atomic-openshift-0:3.11.51-1.git.0.1560686.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
atomic-openshift-cluster-autoscaler-0:3.11.51-1.git.0.0aa9fc2.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
atomic-openshift-descheduler-0:3.11.51-1.git.300.89070e8.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
atomic-openshift-dockerregistry-0:3.11.51-1.git.446.d29ce0e.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
atomic-openshift-metrics-server-0:3.11.51-1.git.52.03e3a91.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
atomic-openshift-node-problem-detector-0:3.11.51-1.git.254.22189b0.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
atomic-openshift-service-idler-0:3.11.51-1.git.14.813574a.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
atomic-openshift-web-console-0:3.11.51-1.git.324.0ae64ed.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
cri-o-0:1.11.10-1.rhaos3.11.git42c86f0.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
golang-github-openshift-oauth-proxy-0:3.11.51-1.git.419.1af74df.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
golang-github-prometheus-alertmanager-0:3.11.51-1.git.0.50a0687.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
golang-github-prometheus-node_exporter-0:3.11.51-1.git.1063.12dd8be.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
golang-github-prometheus-prometheus-0:3.11.51-1.git.5023.0ad933c.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
jenkins-0:2.138.2.1542054911-1.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
jenkins-2-plugins-0:3.11.1542061886-1.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
kibana-0:5.6.13-1.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
openshift-ansible-0:3.11.51-2.git.0.51c90a3.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
openshift-enterprise-autoheal-0:3.11.51-1.git.219.8ea4275.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
openshift-enterprise-cluster-capacity-0:3.11.51-1.git.380.ffa21af.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
openshift-monitor-project-lifecycle-0:3.11.51-1.git.59.7b59e29.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.11
openshift-monitor-sample-app-0:3.11.51-1.git.5.f6d0188.el7
Fixed · RHBA-2018:3743
Red Hat OpenShift Container Platform 3.10
jenkins
Will not fix
Red Hat OpenShift Container Platform 3.4
jenkins
Will not fix
Red Hat OpenShift Container Platform 3.5
jenkins
Will not fix
Red Hat OpenShift Container Platform 3.6
jenkins
Will not fix
Red Hat OpenShift Container Platform 3.7
jenkins
Will not fix
Red Hat OpenShift Container Platform 3.9
jenkins
Will not fix
Red Hat OpenShift Container Platform 4
jenkins
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Container Platform 3.11 | atomic-enterprise-service-catalog-1:3.11.51-1.git.1671.2d16650.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-0:3.11.51-1.git.0.1560686.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-cluster-autoscaler-0:3.11.51-1.git.0.0aa9fc2.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-descheduler-0:3.11.51-1.git.300.89070e8.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-dockerregistry-0:3.11.51-1.git.446.d29ce0e.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-metrics-server-0:3.11.51-1.git.52.03e3a91.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-node-problem-detector-0:3.11.51-1.git.254.22189b0.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-service-idler-0:3.11.51-1.git.14.813574a.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | atomic-openshift-web-console-0:3.11.51-1.git.324.0ae64ed.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | cri-o-0:1.11.10-1.rhaos3.11.git42c86f0.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | golang-github-openshift-oauth-proxy-0:3.11.51-1.git.419.1af74df.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | golang-github-prometheus-alertmanager-0:3.11.51-1.git.0.50a0687.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | golang-github-prometheus-node_exporter-0:3.11.51-1.git.1063.12dd8be.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | golang-github-prometheus-prometheus-0:3.11.51-1.git.5023.0ad933c.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | jenkins-0:2.138.2.1542054911-1.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | jenkins-2-plugins-0:3.11.1542061886-1.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | kibana-0:5.6.13-1.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | openshift-ansible-0:3.11.51-2.git.0.51c90a3.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | openshift-enterprise-autoheal-0:3.11.51-1.git.219.8ea4275.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | openshift-enterprise-cluster-capacity-0:3.11.51-1.git.380.ffa21af.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | openshift-monitor-project-lifecycle-0:3.11.51-1.git.59.7b59e29.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.11 | openshift-monitor-sample-app-0:3.11.51-1.git.5.f6d0188.el7 | Fixed | RHBA-2018:3743 |
| Red Hat OpenShift Container Platform 3.10 | jenkins | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.4 | jenkins | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.5 | jenkins | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.6 | jenkins | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.7 | jenkins | Will not fix | n/a |
| Red Hat OpenShift Container Platform 3.9 | jenkins | Will not fix | n/a |
| Red Hat OpenShift Container Platform 4 | jenkins | Not affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (9)
- http://www.securityfocus.com/bid/106532 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2018-1000407 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1642879 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-4215 Advisory
- https://github.com/advisories/GHSA-hv45-5j9h-7fhg Advisory
- https://github.com/jenkinsci/jenkins/commit/df87e12ddcfeafdba6e0de0e07b3e21f8473ece6
- https://jenkins.io/security/advisory/2018-10-10/#SECURITY-1129 x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-1000407
- https://www.cve.org/CVERecord?id=CVE-2018-1000407
| Link | Providers | Tags |
|---|---|---|
| http://www.securityfocus.com/bid/106532 | vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry | |
| https://access.redhat.com/security/cve/CVE-2018-1000407 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1642879 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-4215 | Advisory | |
| https://github.com/advisories/GHSA-hv45-5j9h-7fhg | Advisory | |
| https://github.com/jenkinsci/jenkins/commit/df87e12ddcfeafdba6e0de0e07b3e21f8473ece6 | ||
| https://jenkins.io/security/advisory/2018-10-10/#SECURITY-1129 | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-1000407 | ||
| https://www.cve.org/CVERecord?id=CVE-2018-1000407 |
Change history (0)
No recorded changes yet.