Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not escape the reason why a queue items is blcoked in tooltips, resulting in a stored XSS vulnerability exploitable by users able to control parts of the reason a queue item is blocked, such as label expressions not matching any idle executors.
CVSS Details
- CVSS 3.1 Base Score: 5.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade jenkins | Jan 3, 2020 | Sep 25, 2019 |
| Freebsd | — | Upgrade jenkinsUpgrade jenkins-lts | Sep 26, 2019 | Sep 25, 2019 |
| Jenkins 2019 09 25 | — | Upgrade Jenkins to version 2.197Upgrade Jenkins LTS to the latest versionUpgrade Jenkins to the latest versionUpgrade Jenkins LTS to version 2.176.4 | Oct 8, 2019 | Sep 25, 2019 |
| Jenkins 2019 09 25_cve 2019 10403 | — | — | Oct 23, 2019 | Sep 25, 2019 |
| Redhat Openshift | — | Upgrade jenkins | Dec 29, 2020 | Sep 25, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub