jenkins-plugin/workflow-support: Stored XSS vulnerability in Pipeline: Supporting APIs Plugin
Published Oct 19, 2022
8.0
HIGHCVSS 3.1
EPSS 0.71%
Description
Jenkins Pipeline: Supporting APIs Plugin 838.va_3a_087b_4055b and earlier does not sanitize or properly encode URLs of hyperlinks sending POST requests in build logs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create Pipelines.
Affected products
-
Affected
- ≥ unspecified, ≤ 838.va_3a_087b_4055b
Unaffected
- 827.829.v01c0a_3d76c4f
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Jenkins project | Jenkins Pipeline: Supporting APIs Plugin | unknown | Affected
Unaffected
|
No data.
OCP-Tools-4.12-RHEL-8
jenkins-2-plugins-0:4.12.1675702407-1.el8
Fixed · RHSA-2023:1064
OpenShift Developer Tools and Services for OCP 4.11
jenkins-2-plugins-0:4.11.1683009941-1.el8
Fixed · RHSA-2023:3198
Red Hat OpenShift Container Platform 4.10
jenkins-2-plugins-0:4.10.1675144701-1.el8
Fixed · RHSA-2023:0560
Red Hat OpenShift Container Platform 4.9
jenkins-2-plugins-0:4.9.1675668922-1.el8
Fixed · RHSA-2023:0777
Red Hat OpenShift Container Platform 3.11
jenkins-2-plugins
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| OCP-Tools-4.12-RHEL-8 | jenkins-2-plugins-0:4.12.1675702407-1.el8 | Fixed | RHSA-2023:1064 |
| OpenShift Developer Tools and Services for OCP 4.11 | jenkins-2-plugins-0:4.11.1683009941-1.el8 | Fixed | RHSA-2023:3198 |
| Red Hat OpenShift Container Platform 4.10 | jenkins-2-plugins-0:4.10.1675144701-1.el8 | Fixed | RHSA-2023:0560 |
| Red Hat OpenShift Container Platform 4.9 | jenkins-2-plugins-0:4.9.1675668922-1.el8 | Fixed | RHSA-2023:0777 |
| Red Hat OpenShift Container Platform 3.11 | jenkins-2-plugins | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (9)
- http://www.openwall.com/lists/oss-security/2022/10/19/3 mailing-listMailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2022-43409 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2136391 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-7034 Advisory
- https://github.com/advisories/GHSA-64r9-x74q-wxmh Advisory
- https://github.com/jenkinsci/workflow-support-plugin/commit/35e2736cfd5c56799eece176328906d92b6a0dd1
- https://nvd.nist.gov/vuln/detail/CVE-2022-43409
- https://www.cve.org/CVERecord?id=CVE-2022-43409
- https://www.jenkins.io/security/advisory/2022-10-19/#SECURITY-2881 Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| http://www.openwall.com/lists/oss-security/2022/10/19/3 | mailing-listMailing ListThird Party Advisory | |
| https://access.redhat.com/security/cve/CVE-2022-43409 | Vendor Advisory | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2136391 | Issue Tracking | |
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-7034 | Advisory | |
| https://github.com/advisories/GHSA-64r9-x74q-wxmh | Advisory | |
| https://github.com/jenkinsci/workflow-support-plugin/commit/35e2736cfd5c56799eece176328906d92b6a0dd1 | ||
| https://nvd.nist.gov/vuln/detail/CVE-2022-43409 | ||
| https://www.cve.org/CVERecord?id=CVE-2022-43409 | ||
| https://www.jenkins.io/security/advisory/2022-10-19/#SECURITY-2881 | Vendor Advisory |
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
GitHub