CVE-2017-1000102
published 2017-10-05CVE-2017-1000102: The Details view of some Static Analysis Utilities based plugins, was vulnerable to a persisted cross-site scripting vulnerability: Malicious users able to…
PriorityP423medium5.4CVSS 3.0
AVNACLPRLUIRSCCLILAN
EPSS
0.74%
50.4th percentile
The Details view of some Static Analysis Utilities based plugins, was vulnerable to a persisted cross-site scripting vulnerability: Malicious users able to influence the input to these plugins, for example the console output which is parsed to extract build warnings (Warnings Plugin), could insert arbitrary HTML into this view.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | blue_ocean_plugin | — | — |
| jenkins | config_file_provider_plugin | — | — |
| jenkins | credentials_plugin | — | — |
| jenkins | datadog_plugin | — | — |
| jenkins | deploy_to_container_plugin | — | — |
| jenkins | dry_plugin | — | — |
| jenkins | groovy_plugin | — | — |
| jenkins | input_step_plugin | — | — |
| jenkins | owasp_dependency-check_plugin | — | — |
| jenkins | script_security_plugin | — | — |
| jenkins | static_analysis_utilities | <= 1.91 | — |
| jenkins | static_analysis_utilities_plugin | — | — |
| jenkins | warnings_plugin | — | — |
CVSS provenance
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
nvdv2.03.5LOWAV:N/AC:M/Au:S/C:N/I:P/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
OSV
Persistent XSS vulnerability in Static Analysis Utilities
osv·2022-05-17
CVE-2017-1000102 [MEDIUM] Persistent XSS vulnerability in Static Analysis Utilities
Persistent XSS vulnerability in Static Analysis Utilities
The Details view of some Static Analysis Utilities based plugins, was vulnerable to a persisted cross-site scripting vulnerability: Malicious users able to influence the input to these plugins, for example the console output which is parsed to extract build warnings (Warnings Plugin), could insert arbitrary HTML into this view.
GHSA
Persistent XSS vulnerability in Static Analysis Utilities
ghsa·2022-05-17
CVE-2017-1000102 [MEDIUM] CWE-79 Persistent XSS vulnerability in Static Analysis Utilities
Persistent XSS vulnerability in Static Analysis Utilities
The Details view of some Static Analysis Utilities based plugins, was vulnerable to a persisted cross-site scripting vulnerability: Malicious users able to influence the input to these plugins, for example the console output which is parsed to extract build warnings (Warnings Plugin), could insert arbitrary HTML into this view.
Jenkins
Jenkins Security Advisory 2017-08-07
vendor_jenkins·2017-08-07·CVSS 5.4
CVE-2017-1000102 [MEDIUM] Jenkins Security Advisory 2017-08-07
Title: Jenkins Security Advisory 2017-08-07
Jenkins Security Advisory 2017-08-07
This advisory announces vulnerabilities in these Jenkins plugins:
Blue Ocean
Config File Provider Plugin
Datadog Plugin
Deploy to container Plugin
DRY Plugin
OWASP Dependency-Check Plugin
Pipeline: Groovy Plugin
Pipeline: Input Step Plugin
Script Security Plugin
Static Analysis Utilities Plugin
Description
Persistent XSS vulnerability in Static Analysis Utilities and DRY Plugins
SECURITY-467 / CVE-2017-1000102 (Static Analysis Utilities Plugin) / CVE-2017-1000103 (DRY Plugin)
The "Details" view of Static Analysis Utilities based plugins, as well as the custom "Details" view of the DRY Plugin, was vulnerable to a persisted cross-site
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2017-10-05
Published