Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape display names and IDs of item types shown on the New Item page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to specify display names or IDs of item types.
CVSS Details
- CVSS 3.1 Base Score: 5.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade jenkins | Aug 22, 2024 | Jan 13, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 13, 2021 |
| Jenkins 2021 01 13 | — | Upgrade Jenkins to the latest versionUpgrade Jenkins LTS to version 2.263.2Upgrade Jenkins LTS to the latest versionUpgrade Jenkins to version 2.275 | Dec 2, 2021 | Jan 13, 2021 |
| Redhat Openshift | — | Upgrade openstack-ironicUpgrade toolboxUpgrade openstack-ironic-python-agentUpgrade rust-afterburnUpgrade python-ironic-libUpgrade conmonUpgrade python-sushy-oem-idracUpgrade python-keystoneauth1Upgrade cri-oUpgrade ostreeUpgrade python-oslo-upgradecheckUpgrade python-jsonschemaUpgrade python-eventletUpgrade python-hardwareUpgrade python-toozUpgrade machine-config-daemonUpgrade python-kubernetesUpgrade python-sushyUpgrade ignitionUpgrade python-openshiftUpgrade python-stevedoreUpgrade openshiftUpgrade python-oslo-serviceUpgrade rteval-loadsUpgrade python-oslo-serializationUpgrade python-oslo-logUpgrade butaneUpgrade openshift-clientsUpgrade redhat-release-coreosUpgrade coreos-installerUpgrade console-login-helper-messagesUpgrade python-oslo-contextUpgrade cri-toolsUpgrade ironic-images-ipa-ppc64leUpgrade runcUpgrade jenkins-2-pluginsUpgrade openshift-kuryrUpgrade python-oslo-dbUpgrade python-pyrsistentUpgrade python-oslo-policyUpgrade python-debtcollectorUpgrade python-oslo-concurrencyUpgrade ironic-imagesUpgrade openvswitch2.15Upgrade python-oslo-i18nUpgrade ovn2.13Upgrade python-ironic-prometheus-exporterUpgrade jenkinsUpgrade haproxyUpgrade python-openstacksdkUpgrade ironic-images-ipa-x86_64Upgrade python-oslo-utilsUpgrade openshift-ansibleUpgrade openstack-ironic-inspectorUpgrade podmanUpgrade kata-containersUpgrade python-oslo-configUpgrade atomic-openshift-service-idler | Feb 19, 2021 | Jan 13, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub