Improper Neutralization of Input During Web Page Generation in Jenkins
Moderate severity
GitHub Reviewed
Published
May 13, 2022
to the GitHub Advisory Database
•
Updated Oct 26, 2023
Package
Affected versions
<= 2.164.1
>= 2.165, <= 2.171
Patched versions
2.164.2
2.172
Description
Published by the National Vulnerability Database
Apr 10, 2019
Published to the GitHub Advisory Database
May 13, 2022
Reviewed
Jun 29, 2022
Last updated
Oct 26, 2023
The f:validateButton form control for the Jenkins UI did not properly escape job URLs in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, resulting in a cross-site scripting (XSS) vulnerability exploitable by users with the ability to control job names.
References