A cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.1 and earlier in configfiles.jelly, providerlist.jelly that allows users with the ability to configure configuration files to insert arbitrary HTML into some pages in Jenkins.
References
Link Resource
http://www.securityfocus.com/bid/106532 Third Party Advisory VDB Entry
https://jenkins.io/security/advisory/2018-09-25/#SECURITY-1080 Third Party Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: mitre

Published: 2019-01-09T23:00:00

Updated: 2019-01-14T10:57:01

Reserved: 2019-01-09T00:00:00


Link: CVE-2018-1000413

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2019-01-09T23:29:02.513

Modified: 2023-01-31T20:15:43.763


Link: CVE-2018-1000413

JSON object: View

cve-icon Redhat Information

No data.

CWE