Bug 1609624 (CVE-2018-1999007) - CVE-2018-1999007 jenkins: HTTP 404 error pages do not escape URLs when Stapler framework used in debug mode, allowing for XSS
Summary: CVE-2018-1999007 jenkins: HTTP 404 error pages do not escape URLs when Staple...
Keywords:
Status: CLOSED ERRATA
Alias: CVE-2018-1999007
Product: Security Response
Classification: Other
Component: vulnerability
Version: unspecified
Hardware: All
OS: Linux
medium
medium
Target Milestone: ---
Assignee: Red Hat Product Security
QA Contact:
URL:
Whiteboard:
Depends On: 1609625 1610636
Blocks: 1609611
TreeView+ depends on / blocked
 
Reported: 2018-07-30 03:43 UTC by Sam Fowler
Modified: 2021-10-25 09:49 UTC (History)
12 users (show)

Fixed In Version: jenkins 2.133, jenkins 2.121.2
Doc Type: If docs needed, set a value
Doc Text:
Clone Of:
Environment:
Last Closed: 2021-10-25 09:49:31 UTC
Embargoed:


Attachments (Terms of Use)

Description Sam Fowler 2018-07-30 03:43:08 UTC
Stapler is the web framework used by Jenkins to route HTTP requests. When its debug mode is enabled, HTTP 404 error pages display diagnostic information. Those error pages did not escape parts of URLs they displayed, in rare cases resulting in a cross-site scripting vulnerability.


External Reference:

https://jenkins.io/security/advisory/2018-07-18/#SECURITY-390

Comment 1 Sam Fowler 2018-07-30 03:43:34 UTC
Created jenkins tracking bugs for this issue:

Affects: fedora-all [bug 1609625]


Note You need to log in before you can comment on or make changes to this bug.