Cross-Site Request Forgery in Jenkins Credentials Plugin
Moderate severity
GitHub Reviewed
Published
Jun 16, 2021
to the GitHub Advisory Database
•
Updated Dec 26, 2023
Package
Affected versions
>= 2.3.16, < 2.3.19
= 2.3.15
= 2.3.14
>= 2.3.8, < 2.3.13.1
>= 2.3.1, < 2.3.7.1
< 2.3.0.1
Patched versions
2.3.19
2.3.15.1
2.3.14.1
2.3.13.1
2.3.7.1
2.3.0.1
Description
Published by the National Vulnerability Database
May 11, 2021
Reviewed
May 19, 2021
Published to the GitHub Advisory Database
Jun 16, 2021
Last updated
Dec 26, 2023
Jenkins Credentials Plugin prior to 2.3.19, 2.3.15.1, 2.3.14.1, 2.3.13.1, 2.3.7.1, and 2.3.0.1 does not escape user-controlled information on a view it provides, resulting in a reflected cross-site scripting (XSS) vulnerability.
Jenkins Credentials Plugin 2.3.19, 2.3.15.1, 2.3.14.1, 2.3.13.1, 2.3.7.1, and 2.3.0.1 restricts the user-controlled information it provides to a safe subset.
References