CVE-2017-1000389
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Some URLs provided by Jenkins global-build-stats plugin version 1.4 and earlier returned a JSON response that contained request parameters. These responses had the Content Type: text/html, so could have been interpreted as HTML by clients, resulting in a potential reflected cross-site scripting vulnerability. Additionally, some URLs provided by global-build-stats plugin that modify data did not require POST requests to be sent, resulting in a potential cross-site request forgery vulnerability.
Algunas URL proporcionadas por el plugin Jenkins global-build-stats en su versión 1.4 y anteriores devolvía una respuesta JSON que contenía parámetros de peticiones. Estas respuestas tenían el Content Type: text/html, por lo que podrían interpretarse como HTML por los clientes, lo que resulta en una potencial vulnerabilidad de Cross-Site Scripting (XSS). Además, algunas URL proporcionadas por el plugin global-build-stats que modifican datos no requerían que las peticiones POST se enviasen, lo que resulta en una potencial vulnerabilidad de Cross-Site Request Forgery (CSRF).
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-11-29 CVE Reserved
- 2018-01-26 CVE Published
- 2024-08-05 CVE Updated
- 2024-10-08 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://jenkins.io/security/advisory/2017-10-23 | 2018-02-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Jenkins Search vendor "Jenkins" | Global-build-stats Search vendor "Jenkins" for product "Global-build-stats" | <= 1.4 Search vendor "Jenkins" for product "Global-build-stats" and version " <= 1.4" | jenkins |
Affected
|