vendor:
Jenkins build-metrics plugin
by:
vesche (Austin Jackson)
6.1
CVSS
MEDIUM
Cross-Site Scripting
79
CWE
Product Name: Jenkins build-metrics plugin
Affected Version From: Jenkins build-metrics plugin 1.3
Affected Version To: Jenkins build-metrics plugin 1.3 and below
Patch Exists: YES
Related CWE: CVE-2019-10475
CPE: a:jenkins:jenkins_build-metrics_plugin:1.3
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Debian 10 (Buster), Jenkins 2.203 (latest 2019-11-05)
2019
Jenkins build-metrics plugin 1.3 – ‘label’ Cross-Site Scripting
Jenkins build-metrics plugin 1.3 and below is vulnerable to Cross-Site Scripting. This allows an attacker to inject arbitrary JavaScript code into the application, which is then executed in the browser of the victim. This vulnerability is due to insufficient validation of user-supplied input in the 'label' parameter of the 'getBuildStats' API. An attacker can exploit this vulnerability by sending a maliciously crafted request to the vulnerable API.
Mitigation:
Upgrade to Jenkins build-metrics plugin 1.4 or later.