vendor:
Jenkins CI
by:
Christian Catalano
4,7
CVSS
LOW
HTML Injection
79
CWE
Product Name: Jenkins CI
Affected Version From: Jenkins CI v 1.523
Affected Version To: Jenkins CI v 1.523
Patch Exists: NO
Related CWE: CVE-2013-5573
CPE: a:jenkins:jenkins_ci
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: None
2013
Default markup formatter permits offsite-bound forms
The default installation and configuration of Jenkins CI is prone to a security vulnerability. The Jenkins CI default markup formatter permits offsite-bound forms. This vulnerability could be exploited by a remote attacker (a malicious user) to inject malicious persistent HTML script code (application side). To reproduce the vulnerability, the attacker (a malicious user) can add the malicious HTML script code in the 'Descriotion' input field and click on save button. The code execution happens when the victim (an unaware user) view the 'People List' and click on attacker user id.
Mitigation:
Ensure that the default installation and configuration of Jenkins CI is not prone to a security vulnerability.