Description
Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not escape the reason why a queue items is blcoked in tooltips, resulting in a stored XSS vulnerability exploitable by users able to control parts of the reason a queue item is blocked, such as label expressions not matching any idle executors.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-3431 | Jenkins 2.196 and earlier, LTS 2.176.3 and earlier did not escape the reason why a queue items is blcoked in tooltips, resulting in a stored XSS vulnerability exploitable by users able to control parts of the reason a queue item is blocked, such as label expressions not matching any idle executors. |
Github GHSA |
GHSA-9qgf-4fpf-cmh2 | Improper Neutralization of Input During Web Page Generation in Jenkins |
References
History
No history.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-04T22:24:16.950Z
Reserved: 2019-03-29T00:00:00.000Z
Link: CVE-2019-10404
No data.
Status : Modified
Published: 2019-09-25T16:15:10.633
Modified: 2024-11-21T04:19:03.790
Link: CVE-2019-10404
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA