CVE-2018-1000170

MEDIUM

Jenkins < 2.105, < 2.107.1, 2.108-2.115 - Stored Cross-Site Scripting via Item Name

Title source: llm
STIX 2.1

Description

A cross-site scripting vulnerability exists in Jenkins 2.115 and older, LTS 2.107.1 and older, in confirmationList.jelly and stopButton.jelly that allows attackers with Job/Configure and/or Job/Create permission to create an item name containing JavaScript that would be executed in another user's browser when that other user performs some UI actions.

References (1)

Core 1
Core References

Scores

CVSS v3 5.4
EPSS 0.0022
EPSS Percentile 43.8%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Details

CWE
CWE-79
Status published
Products (3)
jenkins/jenkins < 2.105
jenkins/jenkins < 2.107.1
org.jenkins-ci.main/jenkins-core 2.108 - 2.116Maven
Published Apr 16, 2018
Tracked Since Feb 18, 2026