Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape button labels in the Jenkins UI, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with the ability to control button labels.
CVSS Details
- CVSS 3.1 Base Score: 5.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade jenkins | Aug 22, 2024 | Jan 13, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 13, 2021 |
| Jenkins 2021 01 13 | — | Upgrade Jenkins LTS to version 2.263.2Upgrade Jenkins to the latest versionUpgrade Jenkins LTS to the latest versionUpgrade Jenkins to version 2.275 | Dec 2, 2021 | Jan 13, 2021 |
| Redhat Openshift | — | Upgrade openvswitch2.15Upgrade openshift-ansibleUpgrade python-oslo-dbUpgrade toolboxUpgrade python-oslo-upgradecheckUpgrade ignitionUpgrade ironic-images-ipa-x86_64Upgrade haproxyUpgrade python-eventletUpgrade python-oslo-policyUpgrade jenkins-2-pluginsUpgrade python-ironic-prometheus-exporterUpgrade python-sushyUpgrade python-stevedoreUpgrade python-hardwareUpgrade python-oslo-utilsUpgrade python-oslo-serviceUpgrade python-toozUpgrade ironic-imagesUpgrade cri-toolsUpgrade python-pyrsistentUpgrade butaneUpgrade python-oslo-i18nUpgrade jenkinsUpgrade openshift-kuryrUpgrade python-oslo-configUpgrade ironic-images-ipa-ppc64leUpgrade cri-oUpgrade openshift-clientsUpgrade python-oslo-serializationUpgrade python-oslo-concurrencyUpgrade redhat-release-coreosUpgrade machine-config-daemonUpgrade python-openstacksdkUpgrade ovn2.13Upgrade coreos-installerUpgrade runcUpgrade python-kubernetesUpgrade openstack-ironic-python-agentUpgrade python-keystoneauth1Upgrade conmonUpgrade rteval-loadsUpgrade python-oslo-contextUpgrade console-login-helper-messagesUpgrade openstack-ironic-inspectorUpgrade ostreeUpgrade python-ironic-libUpgrade python-sushy-oem-idracUpgrade openstack-ironicUpgrade atomic-openshift-service-idlerUpgrade rust-afterburnUpgrade python-jsonschemaUpgrade openshiftUpgrade podmanUpgrade python-openshiftUpgrade python-oslo-logUpgrade python-debtcollectorUpgrade kata-containers | Feb 19, 2021 | Jan 13, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub