Cross-Site Scripting Vulnerability in Jenkins 2.115 and Older

Cross-Site Scripting Vulnerability in Jenkins 2.115 and Older

CVE-2018-1000170 · LOW Severity


A cross-site scripting vulnerability exists in Jenkins 2.115 and older, LTS 2.107.1 and older, in confirmationList.jelly and stopButton.jelly that allows attackers with Job/Configure and/or Job/Create permission to create an item name containing JavaScript that would be executed in another user's browser when that other user performs some UI actions.

Learn more about our User Device Pen Test.