Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not restrict or filter values set as Jenkins URL in the global configuration, resulting in a stored XSS vulnerability exploitable by attackers with Overall/Administer permission.
CVSS Details
- CVSS 3.1 Base Score: 4.8
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade jenkins | Jan 3, 2020 | Sep 25, 2019 |
| Freebsd | — | Upgrade jenkins-ltsUpgrade jenkins | Sep 26, 2019 | Sep 25, 2019 |
| Jenkins 2019 09 25 | — | Upgrade Jenkins LTS to the latest versionUpgrade Jenkins to the latest versionUpgrade Jenkins to version 2.197Upgrade Jenkins LTS to version 2.176.4 | Oct 8, 2019 | Sep 25, 2019 |
| Redhat Openshift | — | Upgrade jenkins | Dec 29, 2020 | Sep 25, 2019 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub