The f:validateButton form control for the Jenkins UI did not properly escape job URLs in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, resulting in a cross-site scripting (XSS) vulnerability exploitable by users with the ability to control job names.
CVSS Details
- CVSS 3.1 Base Score: 5.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade jenkins | Jun 21, 2019 | Apr 10, 2019 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Apr 10, 2019 |
| Jenkins 2019 04 10 | — | Upgrade Jenkins to version 2.172Upgrade Jenkins LTS to version 2.164.2Upgrade Jenkins to the latest versionUpgrade Jenkins LTS to the latest version | Apr 12, 2019 | Apr 10, 2019 |
| Redhat Openshift | — | Upgrade atomic-enterprise-service-catalogUpgrade cri-oUpgrade atomic-openshift-cluster-autoscalerUpgrade jenkins-2-pluginsUpgrade golang-github-prometheus-alertmanagerUpgrade atomic-openshift-dockerregistryUpgrade openshift-enterprise-cluster-capacityUpgrade golang-github-prometheus-prometheusUpgrade golang-github-prometheus-node_exporterUpgrade atomic-openshift-deschedulerUpgrade jenkinsUpgrade atomic-openshift-service-idlerUpgrade atomic-openshift-node-problem-detectorUpgrade openshift-enterprise-autohealUpgrade golang-github-openshift-oauth-proxyUpgrade atomic-openshift-web-consoleUpgrade openshift-ansibleUpgrade atomic-openshift-metrics-server | Jul 4, 2019 | Apr 10, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub