Bug 890612 (CVE-2012-6074) - CVE-2012-6074 Jenkins: cross-site scripting vulnerability
Summary: CVE-2012-6074 Jenkins: cross-site scripting vulnerability
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2012-6074
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 890614 890615
Blocks: 890613
TreeView+ depends on / blocked
 
Reported: 2012-12-28 06:03 UTC by Kurt Seifried
Modified: 2019-09-29 12:58 UTC (History)
5 users (show)

Fixed In Version:
Doc Type: Bug Fix
Doc Text:
Clone Of:
Environment:
Last Closed: 2013-04-23 13:09:21 UTC
Embargoed:


Attachments (Terms of Use)


Links
System ID Private Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2013:0220 0 normal SHIPPED_LIVE Important: Red Hat OpenShift Enterprise 1.1 update 2013-02-01 01:23:24 UTC

Description Kurt Seifried 2012-12-28 06:03:39 UTC
Jenkins Security Advisory 2012-11-20

The third vulnerability is a cross-site scripting vulnerability that allows 
an attacker with some degree of write access in Jenkins to embed malicious 
JavaScript into pages generated by Jenkins.

Fix:
Main line users should upgrade to Jenkins 1.491
LTS users should upgrade to 1.480.1

External URLs:
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2012-11-20
http://www.cloudbees.com/jenkins-advisory/jenkins-security-advisory-2012-11-20.cb

Comment 3 errata-xmlrpc 2013-01-31 20:34:15 UTC
This issue has been addressed in following products:

  RHEL 6 Version of OpenShift Enterprise

Via RHSA-2013:0220 https://rhn.redhat.com/errata/RHSA-2013-0220.html


Note You need to log in before you can comment on or make changes to this bug.