CVE-2019-1003013 PUBLISHED

Reported by jenkins · Published February 6, 2019

An cross-site scripting vulnerability exists in Jenkins Blue Ocean Plugins 1.10.1 and earlier in blueocean-commons/src/main/java/io/jenkins/blueocean/commons/stapler/Export.java, blueocean-commons/src/main/java/io/jenkins/blueocean/commons/stapler/export/ExportConfig.java, blueocean-commons/src/main/java/io/jenkins/blueocean/commons/stapler/export/JSONDataWriter.java, blueocean-rest-impl/src/main/java/io/jenkins/blueocean/service/embedded/UserStatePreloader.java, blueocean-web/src/main/resources/io/jenkins/blueocean/PageStatePreloadDecorator/header.jelly that allows attackers with permission to edit a user's description in Jenkins to have Blue Ocean render arbitrary HTML when using it as that user.

Affected Products

VendorProductVersions
Jenkins projectJenkins Blue Ocean Plugins1.10.1 and earlier
Jenkins projectJenkins Blue Ocean Plugins1.10.1 and earlier, 1.10.1 and earlier
Mavenio.jenkins.blueocean:blueocean0, 0

Timeline

References

Open in Interactive Console →