Description
The f:validateButton form control for the Jenkins UI did not properly escape job URLs in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, resulting in a cross-site scripting (XSS) vulnerability exploitable by users with the ability to control job names.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5011 | The f:validateButton form control for the Jenkins UI did not properly escape job URLs in Jenkins 2.171 and earlier and Jenkins LTS 2.164.1 and earlier, resulting in a cross-site scripting (XSS) vulnerability exploitable by users with the ability to control job names. |
Github GHSA |
GHSA-qpg9-83fv-x9ch | Improper Neutralization of Input During Web Page Generation in Jenkins |
References
History
No history.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-05T03:07:17.918Z
Reserved: 2019-04-10T00:00:00.000Z
Link: CVE-2019-1003050
No data.
Status : Modified
Published: 2019-04-10T21:29:01.513
Modified: 2024-11-21T04:17:48.740
Link: CVE-2019-1003050
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA