Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Suhas Gaikwad

#43501of 53,639
6.1Total CVSS
Vulnerabilities · 1
PT-2018-7128
6.1
2018-05-10
Cloudbees · Jenkins · CVE-2017-2601
Name of the Vulnerable Software and Affected Versions: Jenkins versions prior to 2.44 Jenkins versions prior to 2.32.2 Description: The issue concerns a persisted cross-site scripting vulnerability in parameter names and descriptions. Users with the permission to configure jobs were able to inject JavaScript into parameter names and descriptions. Recommendations: For versions prior to 2.44, update to version 2.44 or later. For versions prior to 2.32.2, update to version 2.32.2 or later.