Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not implement any restrictions for the URL rendering a formatted preview of markup passed as a query parameter, resulting in a reflected cross-site scripting (XSS) vulnerability if the configured markup formatter does not prohibit unsafe elements (JavaScript) in markup.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade jenkins | Aug 22, 2024 | Jan 13, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 13, 2021 |
| Jenkins 2021 01 13 | — | Upgrade Jenkins to the latest versionUpgrade Jenkins LTS to version 2.263.2Upgrade Jenkins LTS to the latest versionUpgrade Jenkins to version 2.275 | Dec 2, 2021 | Jan 13, 2021 |
| Redhat Openshift | — | Upgrade toolboxUpgrade ignitionUpgrade ironic-imagesUpgrade ovn2.13Upgrade jenkins-2-pluginsUpgrade ironic-images-ipa-ppc64leUpgrade haproxyUpgrade atomic-openshift-service-idlerUpgrade python-ironic-prometheus-exporterUpgrade openshift-kuryrUpgrade butaneUpgrade python-oslo-dbUpgrade python-oslo-configUpgrade podmanUpgrade openshift-clientsUpgrade python-eventletUpgrade python-hardwareUpgrade python-toozUpgrade openstack-ironic-python-agentUpgrade runcUpgrade python-pyrsistentUpgrade openshift-ansibleUpgrade python-oslo-concurrencyUpgrade python-keystoneauth1Upgrade jenkinsUpgrade python-oslo-i18nUpgrade python-openshiftUpgrade conmonUpgrade python-oslo-serializationUpgrade python-oslo-utilsUpgrade coreos-installerUpgrade openvswitch2.15Upgrade machine-config-daemonUpgrade python-jsonschemaUpgrade python-oslo-logUpgrade python-ironic-libUpgrade cri-oUpgrade python-kubernetesUpgrade cri-toolsUpgrade python-sushy-oem-idracUpgrade console-login-helper-messagesUpgrade ironic-images-ipa-x86_64Upgrade openstack-ironicUpgrade openstack-ironic-inspectorUpgrade python-openstacksdkUpgrade rust-afterburnUpgrade python-sushyUpgrade python-oslo-contextUpgrade python-debtcollectorUpgrade python-oslo-upgradecheckUpgrade redhat-release-coreosUpgrade python-stevedoreUpgrade rteval-loadsUpgrade python-oslo-serviceUpgrade ostreeUpgrade python-oslo-policyUpgrade openshiftUpgrade kata-containers | Feb 19, 2021 | Jan 13, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub