Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape button labels in the Jenkins UI, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with the ability to control button labels.
CVSS Details
- CVSS 3.1 Base Score: 5.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade jenkins | Aug 22, 2024 | Jan 13, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 13, 2021 |
| Jenkins 2021 01 13 | — | Upgrade Jenkins to the latest versionUpgrade Jenkins LTS to version 2.263.2Upgrade Jenkins to version 2.275Upgrade Jenkins LTS to the latest version | Dec 2, 2021 | Jan 13, 2021 |
| Redhat Openshift | — | Upgrade toolboxUpgrade cri-toolsUpgrade python-sushyUpgrade openshift-clientsUpgrade python-hardwareUpgrade jenkinsUpgrade cri-oUpgrade python-oslo-i18nUpgrade python-oslo-policyUpgrade openvswitch2.15Upgrade openshift-ansibleUpgrade openshift-kuryrUpgrade jenkins-2-pluginsUpgrade python-oslo-serviceUpgrade python-stevedoreUpgrade python-oslo-dbUpgrade python-ironic-prometheus-exporterUpgrade haproxyUpgrade python-oslo-upgradecheckUpgrade python-oslo-configUpgrade ironic-images-ipa-x86_64Upgrade kata-containersUpgrade python-pyrsistentUpgrade ironic-images-ipa-ppc64leUpgrade python-toozUpgrade python-eventletUpgrade python-oslo-utilsUpgrade butaneUpgrade ignitionUpgrade python-kubernetesUpgrade python-openstacksdkUpgrade python-oslo-concurrencyUpgrade ovn2.13Upgrade redhat-release-coreosUpgrade openstack-ironicUpgrade conmonUpgrade machine-config-daemonUpgrade console-login-helper-messagesUpgrade rteval-loadsUpgrade python-oslo-serializationUpgrade runcUpgrade openstack-ironic-python-agentUpgrade openshiftUpgrade coreos-installerUpgrade python-jsonschemaUpgrade python-openshiftUpgrade podmanUpgrade python-debtcollectorUpgrade atomic-openshift-service-idlerUpgrade python-oslo-logUpgrade rust-afterburnUpgrade python-oslo-contextUpgrade python-keystoneauth1Upgrade ostreeUpgrade openstack-ironic-inspectorUpgrade python-sushy-oem-idracUpgrade python-ironic-libUpgrade ironic-images | Feb 19, 2021 | Jan 13, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub