Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not escape the SCM tag name on the tooltip for SCM tag actions, resulting in a stored XSS vulnerability exploitable by users able to control SCM tag names for these actions.
CVSS Details
- CVSS 3.1 Base Score: 5.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade jenkins | Jan 3, 2020 | Sep 25, 2019 |
| Freebsd | — | Upgrade jenkins-ltsUpgrade jenkins | Sep 26, 2019 | Sep 25, 2019 |
| Jenkins 2019 09 25 | — | Upgrade Jenkins to the latest versionUpgrade Jenkins to version 2.197Upgrade Jenkins LTS to version 2.176.4Upgrade Jenkins LTS to the latest version | Jul 23, 2026 | Sep 25, 2019 |
| Redhat Openshift | — | Upgrade jenkins | Dec 29, 2020 | Sep 25, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub