Lucene search

K
osvGoogleOSV:GHSA-JPVQ-V729-7J2H
HistoryMay 24, 2022 - 5:25 p.m.

Improper Neutralization of Input During Web Page Generation in Jenkins

2022-05-2417:25:24
Google
osv.dev
12
jenkins
web page generation
cross-site scripting
vulnerability
job permission
authentication token

EPSS

0.007

Percentile

80.6%

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via ‘Trigger builds remotely’, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Job/Configure permission or knowledge of the Authentication Token.