CVE-2019-1003014
06.02.2019, 16:29
An cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.4.1 and earlier in src/main/resources/lib/configfiles/configfiles.jelly that allows attackers with permission to define shared configuration files to execute arbitrary JavaScript when a user attempts to delete the shared configuration file.
Vendor | Product | Version |
---|---|---|
jenkins | config_file_provider | 𝑥 ≤ 3.4.1 |
redhat | openshift_container_platform | 3.11 |
𝑥
= Vulnerable software versions
References