Allele Security Alert
ASA-2019-00097
Identifier(s)
ASA-2019-00097, SECURITY-1253, CVE-2019-1003014
Title
Cross-Site Scripting (XSS) vulnerability in Config File Provider Plugin
Vendor(s)
CloudBees, Inc
Product(s)
Jenkins
Affected version(s)
Config File Provider Plugin up to and including 3.4.1
Fixed version(s)
Config File Provider Plugin version 3.5
Proof of concept
Unknown
Description
Config File Provider Plugin improperly handled script names in its JavaScript-based UI, resulting in a stored cross-site scripting (XSS) vulnerability.
Technical details
Unknown
Credits
Adam Willard
Reference(s)
Jenkins Security Advisory 2019-01-28
https://jenkins.io/security/advisory/2019-01-28
Jenkins Plugins
https://plugins.jenkins.io/config-file-provider
CVE-2019-1003014
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-1003014
CVE-2019-1003014
https://nvd.nist.gov/vuln/detail/CVE-2019-1003014
If there is any error in this alert or you wish a comprehensive analysis, let us know.
Last modified: February 24, 2019