In Jenkins 2.196 and earlier, LTS 2.176.3 and earlier, the f:combobox form control interpreted its item labels as HTML, resulting in a stored XSS vulnerability exploitable by users with permission to define its contents.
CVSS Details
- CVSS 3.1 Base Score: 5.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade jenkins | Jan 3, 2020 | Sep 25, 2019 |
| Freebsd | — | Upgrade jenkins-ltsUpgrade jenkins | Sep 26, 2019 | Sep 25, 2019 |
| Jenkins 2019 09 25 | — | Upgrade Jenkins to version 2.197Upgrade Jenkins to the latest versionUpgrade Jenkins LTS to version 2.176.4Upgrade Jenkins LTS to the latest version | Oct 8, 2019 | Sep 25, 2019 |
| Redhat Openshift | — | Upgrade jenkins | Dec 29, 2020 | Sep 25, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub