Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1609624 - (CVE-2018-1999007) CVE-2018-1999007 jenkins: HTTP 404 error pages do not escape URLs when Stapler framework used in debug mode, allowing for XSS
CVE-2018-1999007 jenkins: HTTP 404 error pages do not escape URLs when Staple...
Status: NEW
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
medium Severity medium
: ---
: ---
Assigned To: Red Hat Product Security
impact=moderate,public=20180718,repor...
: Security
Depends On: 1609625 1610636
Blocks: 1609611
  Show dependency treegraph
 
Reported: 2018-07-29 23:43 EDT by Sam Fowler
Modified: 2018-08-01 01:26 EDT (History)
12 users (show)

See Also:
Fixed In Version: jenkins 2.133, jenkins 2.121.2
Doc Type: If docs needed, set a value
Doc Text:
Story Points: ---
Clone Of:
Environment:
Last Closed:
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)

  None (edit)
Description Sam Fowler 2018-07-29 23:43:08 EDT
Stapler is the web framework used by Jenkins to route HTTP requests. When its debug mode is enabled, HTTP 404 error pages display diagnostic information. Those error pages did not escape parts of URLs they displayed, in rare cases resulting in a cross-site scripting vulnerability.


External Reference:

https://jenkins.io/security/advisory/2018-07-18/#SECURITY-390
Comment 1 Sam Fowler 2018-07-29 23:43:34 EDT
Created jenkins tracking bugs for this issue:

Affects: fedora-all [bug 1609625]

Note You need to log in before you can comment on or make changes to this bug.