Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not implement any restrictions for the URL rendering a formatted preview of markup passed as a query parameter, resulting in a reflected cross-site scripting (XSS) vulnerability if the configured markup formatter does not prohibit unsafe elements (JavaScript) in markup.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade jenkins | Aug 22, 2024 | Jan 13, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 13, 2021 |
| Jenkins 2021 01 13 | — | Upgrade Jenkins to the latest versionUpgrade Jenkins to version 2.275Upgrade Jenkins LTS to version 2.263.2Upgrade Jenkins LTS to the latest version | Dec 2, 2021 | Jan 13, 2021 |
| Redhat Openshift | — | Upgrade openshift-kuryrUpgrade jenkinsUpgrade python-oslo-concurrencyUpgrade python-oslo-configUpgrade ironic-imagesUpgrade python-pyrsistentUpgrade openshiftUpgrade butaneUpgrade python-oslo-i18nUpgrade ironic-images-ipa-ppc64leUpgrade python-hardwareUpgrade podmanUpgrade openstack-ironic-python-agentUpgrade python-eventletUpgrade openshift-clientsUpgrade ignitionUpgrade atomic-openshift-service-idlerUpgrade runcUpgrade python-ironic-prometheus-exporterUpgrade python-keystoneauth1Upgrade openshift-ansibleUpgrade python-oslo-dbUpgrade jenkins-2-pluginsUpgrade toolboxUpgrade haproxyUpgrade python-toozUpgrade ovn2.13Upgrade python-oslo-serviceUpgrade python-oslo-upgradecheckUpgrade cri-oUpgrade openstack-ironicUpgrade python-openstacksdkUpgrade python-sushyUpgrade python-debtcollectorUpgrade openstack-ironic-inspectorUpgrade machine-config-daemonUpgrade rteval-loadsUpgrade rust-afterburnUpgrade conmonUpgrade python-oslo-utilsUpgrade ironic-images-ipa-x86_64Upgrade openvswitch2.15Upgrade console-login-helper-messagesUpgrade python-oslo-contextUpgrade python-stevedoreUpgrade redhat-release-coreosUpgrade python-jsonschemaUpgrade python-oslo-serializationUpgrade cri-toolsUpgrade python-ironic-libUpgrade python-openshiftUpgrade python-oslo-logUpgrade ostreeUpgrade python-kubernetesUpgrade coreos-installerUpgrade python-sushy-oem-idracUpgrade python-oslo-policyUpgrade kata-containers | Feb 19, 2021 | Jan 13, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub