[JENKINS:SECURITY-3247] Stored XSS vulnerability in `trac`

Severity High
Affected Packages 2
CVEs 1

trac 1.13 and earlier does not escape the Trac website URL on the build page.

This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

As of publication of this advisory, there is no fix.

ID
JENKINS:SECURITY-3247
Severity
high
Published
2023-10-25T00:00:00
(11 months ago)
Modified
2023-10-25T00:00:00
(11 months ago)
Rights
Jenkins Security Team
Other Advisories
Source # ID Name URL
Plugin repository trac repository https://github.com/jenkinsci/trac-plugin
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:maven/org.jenkins-ci.plugins/trac org.jenkins-ci.plugins trac <= 1.13
Affected pkg:github/jenkinsci/trac-plugin jenkinsci trac-plugin <= 1.13
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...