Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not properly escape node labels that are shown in the form validation for label expressions on job configuration pages, resulting in a stored XSS vulnerability exploitable by users able to define node labels.
CVSS Details
- CVSS 3.1 Base Score: 5.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade jenkins | May 8, 2020 | Mar 25, 2020 |
| Freebsd | — | Upgrade jenkins-ltsUpgrade jenkins | Mar 26, 2020 | Mar 25, 2020 |
| Jenkins 2020 03 25 | — | Upgrade Jenkins LTS to the latest versionUpgrade Jenkins LTS to version 2.204.6Upgrade Jenkins to the latest versionUpgrade Jenkins to version 2.228 | Mar 27, 2020 | Mar 25, 2020 |
| Redhat Openshift | — | Upgrade atomic-openshift-service-idlerUpgrade machine-config-daemonUpgrade openshift-kuryrUpgrade openshift-ansibleUpgrade cri-oUpgrade s390utilsUpgrade openshiftUpgrade atomic-enterprise-service-catalogUpgrade openshift-clientsUpgrade conmonUpgrade jenkins | Dec 29, 2020 | Mar 25, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub