MEDIUM
jenkins: HTTP 404 error pages do not escape URLs when Stapler framework used in debug mode, allowing for XSS
Published Jul 23, 2018
5.4
MEDIUMCVSS 3.1
EPSS 0.89%
Description
A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers with the ability to control the existence of some URLs in Jenkins to define JavaScript that would be executed in another user's browser when that other user views HTTP 404 error pages while Stapler debug mode is enabled.
Affected products
No data.
No data.
Red Hat OpenShift Enterprise 3
jenkins
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat OpenShift Enterprise 3 | jenkins | Affected | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (9)
- https://access.redhat.com/security/cve/CVE-2018-1999007 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1609624 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-2708 Advisory
- https://github.com/advisories/GHSA-6456-xjm5-g3pg Advisory
- https://github.com/jenkinsci/stapler/commit/03e221a81e8424709d1fbdf72ab814309dd8e13f
- https://jenkins.io/security/advisory/2018-07-18/#SECURITY-390 x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2018-1999007
- https://www.cve.org/CVERecord?id=CVE-2018-1999007
- https://www.oracle.com/security-alerts/cpuapr2022.html x_refsource_MISCPatchThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://access.redhat.com/security/cve/CVE-2018-1999007 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=1609624 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-2708 | Advisory | |
| https://github.com/advisories/GHSA-6456-xjm5-g3pg | Advisory | |
| https://github.com/jenkinsci/stapler/commit/03e221a81e8424709d1fbdf72ab814309dd8e13f | ||
| https://jenkins.io/security/advisory/2018-07-18/#SECURITY-390 | x_refsource_CONFIRMVendor Advisory | |
| https://nvd.nist.gov/vuln/detail/CVE-2018-1999007 | ||
| https://www.cve.org/CVERecord?id=CVE-2018-1999007 | ||
| https://www.oracle.com/security-alerts/cpuapr2022.html | x_refsource_MISCPatchThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 23, 2018
Updated Aug 5, 2024
Reserved Jul 18, 2018
Link CVE-2018-1999007
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2022-2708 GHSA-6456-XJM5-G3PG Assigner mitre
Published Jul 23, 2018
Updated Aug 5, 2024
Exploited since n/a
Link EUVD-2022-2708