CVE-2018-1000413

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
09/01/2019
Last modified:
31/01/2023

Description

A cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.1 and earlier in configfiles.jelly, providerlist.jelly that allows users with the ability to configure configuration files to insert arbitrary HTML into some pages in Jenkins.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jenkins:config_file_provider:*:*:*:*:*:jenkins:*:* 3.1 (including)