Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Dhiraj Datar

Researcher fromLakhshya Cyber Security Labs
#50342of 53,633
4.7Total CVSS
Vulnerabilities · 1
PT-2017-14765
4.7
2017-12-06
Cloudbees · Jenkins · CVE-2017-17383
**Name of the Vulnerable Software and Affected Versions** Jenkins versions prior to 2.94 **Description** The issue allows remote authenticated administrators to conduct cross-site scripting (XSS) attacks by crafting a tool name in a job configuration form. This can be demonstrated using the JDK tool in Jenkins core and the Ant tool in the Ant plugin. **Recommendations** For versions prior to 2.94, update to version 2.94 or later to resolve the issue. As a temporary workaround, consider restricting access to job configuration forms to minimize the risk of exploitation.