jenkins: Stored cross-site scripting via build logs
Published Jul 26, 2023
8.0
HIGHCVSS 3.1
EPSS 1.00%
Description
Jenkins 2.415 and earlier, LTS 2.401.2 and earlier does not sanitize or properly encode URLs in build logs when transforming them into hyperlinks, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control build log contents.
Affected products
No data.
No data.
OpenShift Developer Tools and Services
jenkins
Affected
Red Hat OpenShift Container Platform 3.11
jenkins
Out of support scope
Red Hat OpenShift Container Platform 4
jenkins
Affected
| Product | Package | State | Advisory |
|---|---|---|---|
| OpenShift Developer Tools and Services | jenkins | Affected | n/a |
| Red Hat OpenShift Container Platform 3.11 | jenkins | Out of support scope | n/a |
| Red Hat OpenShift Container Platform 4 | jenkins | Affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
OpenShift 3.11 is already in the ELS support model phase. The Jenkins components are out of scope of the ELS support; hence OpenShift 3.11 Jenkins component is marked in this CVE as out of support scope.
References (10)
- http://www.openwall.com/lists/oss-security/2023/07/26/2 Mailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2023-39151 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2226895 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-1976 Advisory
- https://github.com/CVEProject/cvelist/blob/975222d6e43b5b1296dbc8a67d03704a1d2554e8/2023/39xxx/CVE-2023-39151.json
- https://github.com/advisories/GHSA-69vw-3pcm-84rw Advisory
- https://github.com/jenkinsci/jenkins/commit/1b9f1ccdbb7d00705b036d1332908fe52c2cd7ae
- https://nvd.nist.gov/vuln/detail/CVE-2023-39151
- https://www.cve.org/CVERecord?id=CVE-2023-39151
- https://www.jenkins.io/security/advisory/2023-07-26/#SECURITY-3188 vendor-advisoryVendor Advisory
Change history (0)
No recorded changes yet.