Cross-site scripting in Jenkins Kiuwan Plugin
Moderate severity
GitHub Reviewed
Published
Jun 16, 2021
to the GitHub Advisory Database
•
Updated Dec 26, 2023
Package
Affected versions
< 1.6.1
Patched versions
1.6.1
Description
Published by the National Vulnerability Database
Jun 10, 2021
Reviewed
Jun 14, 2021
Published to the GitHub Advisory Database
Jun 16, 2021
Last updated
Dec 26, 2023
Jenkins Kiuwan Plugin 1.6.0 and earlier does not escape query parameters in an error message for a form validation endpoint, resulting in a reflected cross-site scripting (XSS) vulnerability.
Only older releases of Jenkins are affected by this vulnerability. Jenkins 2.275 and newer, LTS 2.263.2 and newer include a protection preventing this from being exploitable.
Jenkins Kiuwan Plugin 1.6.1 escapes affected parts of the error message in the form validation endpoint.
References