ASA-2019-00097 – Jenkins: Cross-Site Scripting (XSS) vulnerability in Config File Provider Plugin


Allele Security Alert

ASA-2019-00097

Identifier(s)

ASA-2019-00097, SECURITY-1253, CVE-2019-1003014

Title

Cross-Site Scripting (XSS) vulnerability in Config File Provider Plugin

Vendor(s)

CloudBees, Inc

Product(s)

Jenkins

Affected version(s)

Config File Provider Plugin up to and including 3.4.1

Fixed version(s)

Config File Provider Plugin version 3.5

Proof of concept

Unknown

Description

Config File Provider Plugin improperly handled script names in its JavaScript-based UI, resulting in a stored cross-site scripting (XSS) vulnerability.

Technical details

Unknown

Credits

Adam Willard

Reference(s)

Jenkins Security Advisory 2019-01-28
https://jenkins.io/security/advisory/2019-01-28

Jenkins Plugins
https://plugins.jenkins.io/config-file-provider

CVE-2019-1003014
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1003014

CVE-2019-1003014
https://nvd.nist.gov/vuln/detail/CVE-2019-1003014

If there is any error in this alert or you wish a comprehensive analysis, let us know.

Last modified: February 24, 2019

We are not responsible for any data loss, device corruption or any other type of issue due to the use of any information mentioned in our security alerts.