Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via 'Trigger builds remotely', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission or knowledge of the Authentication Token.
CVSS Details
- CVSS 3.1 Base Score: 5.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade jenkins | Sep 23, 2020 | Aug 12, 2020 |
| Freebsd | — | Upgrade jenkinsUpgrade jenkins-lts | Aug 13, 2020 | Aug 12, 2020 |
| Jenkins 2020 08 12 | — | Upgrade Jenkins LTS to the latest versionUpgrade Jenkins to version 2.252Upgrade Jenkins to the latest versionUpgrade Jenkins LTS to version 2.235.4 | Dec 2, 2021 | Aug 12, 2020 |
| Redhat Openshift | — | Upgrade jenkins | Dec 29, 2020 | Aug 12, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub