Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape notification bar response contents, resulting in a cross-site scripting (XSS) vulnerability.
CVSS Details
- CVSS 3.1 Base Score: 5.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade jenkins | Aug 22, 2024 | Jan 13, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 13, 2021 |
| Jenkins 2021 01 13 | — | Upgrade Jenkins to version 2.275Upgrade Jenkins LTS to the latest versionUpgrade Jenkins to the latest versionUpgrade Jenkins LTS to version 2.263.2 | Dec 2, 2021 | Jan 13, 2021 |
| Redhat Openshift | — | Upgrade openshift-ansibleUpgrade ironic-images-ipa-ppc64leUpgrade openshift-kuryrUpgrade python-oslo-serializationUpgrade python-oslo-utilsUpgrade python-openshiftUpgrade ovn2.13Upgrade python-oslo-policyUpgrade python-sushyUpgrade python-eventletUpgrade ignitionUpgrade python-oslo-dbUpgrade python-oslo-concurrencyUpgrade butaneUpgrade openstack-ironic-python-agentUpgrade python-hardwareUpgrade ironic-imagesUpgrade runcUpgrade atomic-openshift-service-idlerUpgrade redhat-release-coreosUpgrade podmanUpgrade toolboxUpgrade python-debtcollectorUpgrade console-login-helper-messagesUpgrade jenkins-2-pluginsUpgrade python-oslo-i18nUpgrade python-keystoneauth1Upgrade openshift-clientsUpgrade openshiftUpgrade python-oslo-configUpgrade machine-config-daemonUpgrade python-toozUpgrade openvswitch2.15Upgrade python-ironic-prometheus-exporterUpgrade python-pyrsistentUpgrade python-oslo-contextUpgrade coreos-installerUpgrade openstack-ironicUpgrade python-ironic-libUpgrade python-oslo-serviceUpgrade python-kubernetesUpgrade rust-afterburnUpgrade conmonUpgrade python-oslo-upgradecheckUpgrade python-stevedoreUpgrade cri-oUpgrade ostreeUpgrade python-sushy-oem-idracUpgrade ironic-images-ipa-x86_64Upgrade python-openstacksdkUpgrade openstack-ironic-inspectorUpgrade kata-containersUpgrade jenkinsUpgrade python-oslo-logUpgrade rteval-loadsUpgrade python-jsonschemaUpgrade cri-toolsUpgrade haproxy | Feb 19, 2021 | Jan 13, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub