[role-strategy] Admin only XSS

This issue is archived. You can view it, but you can't modify it. Learn more

XMLWordPrintable

    • 526.v859673312a_14

      Description

      Role-based Authorization Strategy does not escape the roles' name in his tooltip.

      This results in a stored cross-site scripting (XSS) vulnerability exploitable only by attackers with Overall/Administer permission.

      We don't consider it a security vulnerability, because you need administer permission to exploit it and as an administer you can already do all the impact of a XSS.

      Recommendation
      https://www.jenkins.io/doc/developer/security/xss-prevention/

            Assignee:
            Markus Winter
            Reporter:
            Kevin Guerroudj
            Archiver:
            Jenkins Service Account

              Created:
              Updated:
              Resolved:
              Archived: