[JENKINS:SECURITY-3071] Stored XSS vulnerability in `shortcut-job`

Severity High
Affected Packages 2
Fixed Packages 2
CVEs 1

shortcut-job 0.4 and earlier does not escape the shortcut redirection URL.

This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure shortcut jobs.

shortcut-job 0.5 escapes the shortcut redirection URL.

ID
JENKINS:SECURITY-3071
Severity
high
Published
2023-08-16T00:00:00
(13 months ago)
Modified
2023-08-16T00:00:00
(13 months ago)
Rights
Jenkins Security Team
Other Advisories
Source # ID Name URL
Plugin repository shortcut-job repository https://github.com/jenkinsci/shortcut-job-plugin
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.plugins/shortcut-job org.jenkins-ci.plugins shortcut-job <= 0.4
Fixed pkg:maven/org.jenkins-ci.plugins/shortcut-job org.jenkins-ci.plugins shortcut-job = 0.5
Affected pkg:github/jenkinsci/shortcut-job-plugin jenkinsci shortcut-job-plugin <= 0.4
Fixed pkg:github/jenkinsci/shortcut-job-plugin jenkinsci shortcut-job-plugin = 0.5
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...