CVE-2018-1000416

Source
https://nvd.nist.gov/vuln/detail/CVE-2018-1000416
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2018-1000416.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2018-1000416
Aliases
Published
2019-01-09T23:29:02Z
Modified
2024-10-12T03:01:35.411622Z
Severity
  • 6.1 (Medium) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N CVSS Calculator
Summary
[none]
Details

A reflected cross-site scripting vulnerability exists in Jenkins Job Config History Plugin 2.18 and earlier in all Jelly files that shows arbitrary attacker-specified HTML in Jenkins to users with Job/Configure access.

References

Affected packages

Git / github.com/jenkinsci/jobconfighistory-plugin

Affected ranges

Type
GIT
Repo
https://github.com/jenkinsci/jobconfighistory-plugin
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Last affected

Affected versions

jobConfigHistory-1.*

jobConfigHistory-1.10
jobConfigHistory-1.11
jobConfigHistory-1.12
jobConfigHistory-1.13
jobConfigHistory-1.6
jobConfigHistory-1.7
jobConfigHistory-1.8
jobConfigHistory-1.9

jobConfigHistory-2.*

jobConfigHistory-2.0
jobConfigHistory-2.1
jobConfigHistory-2.1.1
jobConfigHistory-2.10
jobConfigHistory-2.12
jobConfigHistory-2.13
jobConfigHistory-2.14
jobConfigHistory-2.15
jobConfigHistory-2.16
jobConfigHistory-2.17
jobConfigHistory-2.18
jobConfigHistory-2.2
jobConfigHistory-2.3
jobConfigHistory-2.4
jobConfigHistory-2.5
jobConfigHistory-2.6
jobConfigHistory-2.8
jobConfigHistory-2.9