Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not implement any restrictions for the URL rendering a formatted preview of markup passed as a query parameter, resulting in a reflected cross-site scripting (XSS) vulnerability if the configured markup formatter does not prohibit unsafe elements (JavaScript) in markup.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade jenkins | Aug 22, 2024 | Jan 13, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 13, 2021 |
| Jenkins 2021 01 13 | — | Upgrade Jenkins LTS to version 2.263.2Upgrade Jenkins to version 2.275Upgrade Jenkins LTS to the latest versionUpgrade Jenkins to the latest version | Dec 2, 2021 | Jan 13, 2021 |
| Redhat Openshift | — | Upgrade openvswitch2.15Upgrade python-debtcollectorUpgrade rust-afterburnUpgrade python-openshiftUpgrade conmonUpgrade python-oslo-contextUpgrade python-kubernetesUpgrade ostreeUpgrade cri-toolsUpgrade python-stevedoreUpgrade python-oslo-serviceUpgrade ironic-images-ipa-x86_64Upgrade python-jsonschemaUpgrade python-oslo-upgradecheckUpgrade coreos-installerUpgrade python-openstacksdkUpgrade python-oslo-utilsUpgrade cri-oUpgrade machine-config-daemonUpgrade rteval-loadsUpgrade openstack-ironicUpgrade console-login-helper-messagesUpgrade python-ironic-libUpgrade python-sushy-oem-idracUpgrade openstack-ironic-inspectorUpgrade python-oslo-serializationUpgrade python-sushyUpgrade python-oslo-logUpgrade redhat-release-coreosUpgrade ignitionUpgrade openshift-clientsUpgrade openstack-ironic-python-agentUpgrade podmanUpgrade python-oslo-policyUpgrade python-pyrsistentUpgrade openshiftUpgrade jenkins-2-pluginsUpgrade python-oslo-dbUpgrade butaneUpgrade ironic-images-ipa-ppc64leUpgrade ironic-imagesUpgrade jenkinsUpgrade ovn2.13Upgrade python-hardwareUpgrade openshift-kuryrUpgrade haproxyUpgrade openshift-ansibleUpgrade python-toozUpgrade toolboxUpgrade python-oslo-concurrencyUpgrade python-oslo-i18nUpgrade python-keystoneauth1Upgrade python-eventletUpgrade kata-containersUpgrade runcUpgrade python-oslo-configUpgrade python-ironic-prometheus-exporterUpgrade atomic-openshift-service-idler | Feb 19, 2021 | Jan 13, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub