Lucene search

K
osvGoogleOSV:GHSA-PGXV-H967-FW2Q
HistoryMay 13, 2022 - 1:01 a.m.

Improper Neutralization of Input During Web Page Generation in Jenkins

2022-05-1301:01:01
Google
osv.dev
13
jenkins
cross-site scripting
vulnerability
web page generation

EPSS

0.001

Percentile

21.7%

A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in BuildTimelineWidget.java, BuildTimelineWidget/control.jelly that allows attackers with Job/Configure permission to define JavaScript that would be executed in another user’s browser when that other user performs some UI actions.

EPSS

0.001

Percentile

21.7%