Jenkins Multiple Security Vulnerabilities
BID:56651
Info
Jenkins Multiple Security Vulnerabilities
| Bugtraq ID: | 56651 |
| Class: | Input Validation Error |
| CVE: |
CVE-2012-6072 CVE-2012-6073 CVE-2012-6074 |
| Remote: | Yes |
| Local: | No |
| Published: | Nov 23 2012 12:00AM |
| Updated: | Dec 28 2012 08:20AM |
| Credit: | Soroush Dalili |
| Vulnerable: |
Jenkins CI Jenkins 1.454 Jenkins CI Jenkins 1.452 |
| Not Vulnerable: | |
Discussion
Jenkins Multiple Security Vulnerabilities
Jenkins is prone to multiple security vulnerabilities because it fails to properly sanitize user-supplied input.
Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing an attacker to steal cookie-based authentication credentials, control how the site is rendered to the user, influence or misrepresent how web content is served, cached, or interpreted, and conduct phishing attacks. Other attacks may also be possible.
Jenkins versions prior to 1.480.1 and 1.491 are vulnerable.
Jenkins is prone to multiple security vulnerabilities because it fails to properly sanitize user-supplied input.
Attacker-supplied HTML or JavaScript code could run in the context of the affected site, potentially allowing an attacker to steal cookie-based authentication credentials, control how the site is rendered to the user, influence or misrepresent how web content is served, cached, or interpreted, and conduct phishing attacks. Other attacks may also be possible.
Jenkins versions prior to 1.480.1 and 1.491 are vulnerable.
Exploit / POC
Jenkins Multiple Security Vulnerabilities
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.
To exploit these issues, an attacker must entice an unsuspecting victim into following a malicious URI.
Solution / Fix
Jenkins Multiple Security Vulnerabilities
Solution:
Vendor updates are available. Please see the references for more information.
Solution:
Vendor updates are available. Please see the references for more information.