A cross-site scripting vulnerability exists in Jenkins S3 Plugin 0.10.12 and older in src/main/resources/hudson/plugins/s3/S3ArtifactsProjectAction/jobMain.jelly that allows attackers able to control file names of uploaded files to define file names containing JavaScript that would be executed in another user's browser when that user performs some UI actions.
References
Link Resource
https://jenkins.io/security/advisory/2018-04-16/ Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2022-10-03T16:21:59

Updated: 2022-10-03T16:21:59

Reserved: 2018-04-16T00:00:00


Link: CVE-2018-1000177

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2018-05-08T15:29:00.457

Modified: 2018-06-13T15:05:05.927


Link: CVE-2018-1000177

JSON object: View

cve-icon Redhat Information

No data.

CWE