Description
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape button labels in the Jenkins UI, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with the ability to control button labels.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-5639 | Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape button labels in the Jenkins UI, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with the ability to control button labels. |
Github GHSA |
GHSA-wv63-gwr9-5c55 | Stored XSS vulnerability in Jenkins button labels |
References
History
No history.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-03T18:16:23.633Z
Reserved: 2021-01-04T00:00:00.000Z
Link: CVE-2021-21608
No data.
Status : Modified
Published: 2021-01-13T16:15:13.837
Modified: 2024-11-21T05:48:41.473
Link: CVE-2021-21608
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA