Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape button labels in the Jenkins UI, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with the ability to control button labels.
CVSS Details
- CVSS 3.1 Base Score: 5.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade jenkins | Aug 22, 2024 | Jan 13, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 13, 2021 |
| Jenkins 2021 01 13 | — | Upgrade Jenkins LTS to version 2.263.2Upgrade Jenkins LTS to the latest versionUpgrade Jenkins to the latest versionUpgrade Jenkins to version 2.275 | Dec 2, 2021 | Jan 13, 2021 |
| Redhat Openshift | — | Upgrade python-oslo-configUpgrade kata-containersUpgrade ironic-images-ipa-ppc64leUpgrade python-oslo-utilsUpgrade python-oslo-upgradecheckUpgrade python-sushyUpgrade python-eventletUpgrade butaneUpgrade python-pyrsistentUpgrade python-toozUpgrade openshift-kuryrUpgrade toolboxUpgrade python-oslo-serviceUpgrade python-hardwareUpgrade python-oslo-i18nUpgrade ironic-imagesUpgrade python-oslo-dbUpgrade python-oslo-policyUpgrade jenkins-2-pluginsUpgrade haproxyUpgrade ironic-images-ipa-x86_64Upgrade openshift-ansibleUpgrade openvswitch2.15Upgrade python-ironic-prometheus-exporterUpgrade ignitionUpgrade cri-toolsUpgrade python-stevedoreUpgrade jenkinsUpgrade cri-oUpgrade openshift-clientsUpgrade atomic-openshift-service-idlerUpgrade python-oslo-concurrencyUpgrade python-kubernetesUpgrade python-oslo-serializationUpgrade conmonUpgrade openstack-ironic-python-agentUpgrade openshiftUpgrade python-openstacksdkUpgrade ostreeUpgrade runcUpgrade python-oslo-contextUpgrade machine-config-daemonUpgrade openstack-ironic-inspectorUpgrade python-debtcollectorUpgrade rteval-loadsUpgrade ovn2.13Upgrade python-jsonschemaUpgrade coreos-installerUpgrade python-oslo-logUpgrade python-openshiftUpgrade rust-afterburnUpgrade openstack-ironicUpgrade python-ironic-libUpgrade python-sushy-oem-idracUpgrade console-login-helper-messagesUpgrade podmanUpgrade python-keystoneauth1Upgrade redhat-release-coreos | Feb 19, 2021 | Jan 13, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub