Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape display names and IDs of item types shown on the New Item page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to specify display names or IDs of item types.
CVSS Details
- CVSS 3.1 Base Score: 5.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade jenkins | Aug 22, 2024 | Jan 13, 2021 |
| Arch Linux | — | Upgrade to the latest version of Arch Linux | Jul 11, 2025 | Jan 13, 2021 |
| Jenkins 2021 01 13 | — | Upgrade Jenkins LTS to version 2.263.2Upgrade Jenkins to the latest versionUpgrade Jenkins to version 2.275Upgrade Jenkins LTS to the latest version | Dec 2, 2021 | Jan 13, 2021 |
| Redhat Openshift | — | Upgrade ironic-images-ipa-ppc64leUpgrade python-oslo-configUpgrade python-oslo-concurrencyUpgrade atomic-openshift-service-idlerUpgrade haproxyUpgrade openvswitch2.15Upgrade python-ironic-prometheus-exporterUpgrade python-oslo-i18nUpgrade kata-containersUpgrade ironic-imagesUpgrade openstack-ironic-inspectorUpgrade podmanUpgrade runcUpgrade openshift-ansibleUpgrade openshift-kuryrUpgrade jenkinsUpgrade jenkins-2-pluginsUpgrade python-openstacksdkUpgrade ovn2.13Upgrade python-oslo-policyUpgrade python-oslo-utilsUpgrade python-debtcollectorUpgrade ironic-images-ipa-x86_64Upgrade python-oslo-dbUpgrade python-pyrsistentUpgrade rteval-loadsUpgrade rust-afterburnUpgrade openstack-ironicUpgrade python-toozUpgrade ostreeUpgrade python-sushyUpgrade openshift-clientsUpgrade python-oslo-logUpgrade openstack-ironic-python-agentUpgrade python-kubernetesUpgrade python-eventletUpgrade machine-config-daemonUpgrade cri-oUpgrade python-oslo-upgradecheckUpgrade redhat-release-coreosUpgrade ignitionUpgrade python-stevedoreUpgrade python-oslo-contextUpgrade toolboxUpgrade python-openshiftUpgrade python-keystoneauth1Upgrade openshiftUpgrade python-hardwareUpgrade python-oslo-serializationUpgrade console-login-helper-messagesUpgrade cri-toolsUpgrade python-jsonschemaUpgrade python-sushy-oem-idracUpgrade python-oslo-serviceUpgrade coreos-installerUpgrade python-ironic-libUpgrade butaneUpgrade conmon | Feb 19, 2021 | Jan 13, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub