PT-2018-7128 · Cloudbees+1 · Jenkins

Mayuri Gaikwad

+1

·

Published

2018-05-10

·

Updated

2022-10-19

·

CVE-2017-2601

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions: Jenkins versions prior to 2.44 Jenkins versions prior to 2.32.2
Description: The issue concerns a persisted cross-site scripting vulnerability in parameter names and descriptions. Users with the permission to configure jobs were able to inject JavaScript into parameter names and descriptions.
Recommendations: For versions prior to 2.44, update to version 2.44 or later. For versions prior to 2.32.2, update to version 2.32.2 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2017-2601
GHSA-R69C-5J7C-VM6Q

Affected Products

Jenkins