First published: Fri Mar 09 2012(Updated: )
Cross-site scripting (XSS) vulnerability in Jenkins before 1.454, Jenkins LTS before 1.424.5, and Jenkins Enterprise 1.400.x before 1.400.0.13 and 1.424.x before 1.424.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0325.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Cloudbees Jenkins | =1.400 | |
Cloudbees Jenkins | =1.400.0.12 | |
Cloudbees Jenkins | =1.424 | |
Cloudbees Jenkins | =1.424.5 | |
Cloudbees Jenkins | =1.400 | |
Cloudbees Jenkins | =1.400.0.12 | |
Cloudbees Jenkins | <=1.453 | |
Jenkins Jenkins | =1.301 | |
Jenkins Jenkins | =1.302 | |
Jenkins Jenkins | =1.303 | |
Jenkins Jenkins | =1.304 | |
Jenkins Jenkins | =1.305 | |
Jenkins Jenkins | =1.306 | |
Jenkins Jenkins | =1.307 | |
Jenkins Jenkins | =1.308 | |
Jenkins Jenkins | =1.309 | |
Jenkins Jenkins | =1.310 | |
Jenkins Jenkins | =1.311 | |
Jenkins Jenkins | =1.312 | |
Jenkins Jenkins | =1.313 | |
Jenkins Jenkins | =1.314 | |
Jenkins Jenkins | =1.315 | |
Jenkins Jenkins | =1.316 | |
Jenkins Jenkins | =1.317 | |
Jenkins Jenkins | =1.318 | |
Jenkins Jenkins | =1.319 | |
Jenkins Jenkins | =1.320 | |
Jenkins Jenkins | =1.321 | |
Jenkins Jenkins | =1.322 | |
Jenkins Jenkins | =1.323 | |
Jenkins Jenkins | =1.324 | |
Jenkins Jenkins | =1.325 | |
Jenkins Jenkins | =1.326 | |
Jenkins Jenkins | =1.327 | |
Jenkins Jenkins | =1.328 | |
Jenkins Jenkins | =1.329 | |
Jenkins Jenkins | =1.330 | |
Jenkins Jenkins | =1.331 | |
Jenkins Jenkins | =1.332 | |
Jenkins Jenkins | =1.333 | |
Jenkins Jenkins | =1.334 | |
Jenkins Jenkins | =1.335 | |
Jenkins Jenkins | =1.336 | |
Jenkins Jenkins | =1.337 | |
Jenkins Jenkins | =1.338 | |
Jenkins Jenkins | =1.339 | |
Jenkins Jenkins | =1.340 | |
Jenkins Jenkins | =1.341 | |
Jenkins Jenkins | =1.342 | |
Jenkins Jenkins | =1.343 | |
Jenkins Jenkins | =1.344 | |
Jenkins Jenkins | =1.345 | |
Jenkins Jenkins | =1.346 | |
Jenkins Jenkins | =1.347 | |
Jenkins Jenkins | =1.348 | |
Jenkins Jenkins | =1.349 | |
Jenkins Jenkins | =1.350 | |
Jenkins Jenkins | =1.351 | |
Jenkins Jenkins | =1.352 | |
Jenkins Jenkins | =1.353 | |
Jenkins Jenkins | =1.354 | |
Jenkins Jenkins | =1.355 | |
Jenkins Jenkins | =1.356 | |
Jenkins Jenkins | =1.357 | |
Jenkins Jenkins | =1.358 | |
Jenkins Jenkins | =1.359 | |
Jenkins Jenkins | =1.360 | |
Jenkins Jenkins | =1.361 | |
Jenkins Jenkins | =1.362 | |
Jenkins Jenkins | =1.363 | |
Jenkins Jenkins | =1.364 | |
Jenkins Jenkins | =1.365 | |
Jenkins Jenkins | =1.366 | |
Jenkins Jenkins | =1.367 | |
Jenkins Jenkins | =1.368 | |
Jenkins Jenkins | =1.369 | |
Jenkins Jenkins | =1.370 | |
Jenkins Jenkins | =1.371 | |
Jenkins Jenkins | =1.372 | |
Jenkins Jenkins | =1.373 | |
Jenkins Jenkins | =1.374 | |
Jenkins Jenkins | =1.375 | |
Jenkins Jenkins | =1.376 | |
Jenkins Jenkins | =1.377 | |
Jenkins Jenkins | =1.378 | |
Jenkins Jenkins | =1.379 | |
Jenkins Jenkins | =1.380 | |
Jenkins Jenkins | =1.382 | |
Jenkins Jenkins | =1.383 | |
Jenkins Jenkins | =1.384 | |
Jenkins Jenkins | =1.386 | |
Jenkins Jenkins | =1.387 | |
Jenkins Jenkins | =1.388 | |
Jenkins Jenkins | =1.389 | |
Jenkins Jenkins | =1.390 | |
Jenkins Jenkins | =1.391 | |
Jenkins Jenkins | =1.392 | |
Jenkins Jenkins | =1.393 | |
Jenkins Jenkins | =1.394 | |
Jenkins Jenkins | =1.395 | |
Jenkins Jenkins | =1.396 | |
Jenkins Jenkins | =1.397 | |
Jenkins Jenkins | =1.398 | |
Jenkins Jenkins | =1.399 | |
Jenkins Jenkins | =1.400 | |
Jenkins Jenkins | =1.401 | |
Jenkins Jenkins | =1.402 | |
Jenkins Jenkins | =1.403 | |
Jenkins Jenkins | =1.404 | |
Jenkins Jenkins | =1.405 | |
Jenkins Jenkins | =1.406 | |
Jenkins Jenkins | =1.407 | |
Jenkins Jenkins | =1.408 | |
Jenkins Jenkins | =1.409 | |
Jenkins Jenkins | =1.409.1 | |
Jenkins Jenkins | =1.409.2 | |
Jenkins Jenkins | =1.410 | |
Jenkins Jenkins | =1.411 | |
Jenkins Jenkins | =1.412 | |
Jenkins Jenkins | =1.413 | |
Jenkins Jenkins | =1.414 | |
Jenkins Jenkins | =1.415 | |
Jenkins Jenkins | =1.416 | |
Jenkins Jenkins | =1.417 | |
Jenkins Jenkins | =1.418 | |
Jenkins Jenkins | =1.419 | |
Jenkins Jenkins | =1.420 | |
Jenkins Jenkins | =1.421 | |
Jenkins Jenkins | =1.422 | |
Jenkins Jenkins | =1.423 | |
Jenkins Jenkins | =1.424 | |
Jenkins Jenkins | =1.425 | |
Jenkins Jenkins | =1.426 | |
Jenkins Jenkins | =1.427 | |
Jenkins Jenkins | =1.428 | |
Jenkins Jenkins | =1.429 | |
Jenkins Jenkins | =1.430 | |
Jenkins Jenkins | =1.431 | |
Jenkins Jenkins | =1.432 | |
Jenkins Jenkins | =1.433 | |
Jenkins Jenkins | =1.434 | |
Jenkins Jenkins | =1.435 | |
Jenkins Jenkins | =1.436 | |
Jenkins Jenkins | =1.437 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-0324 has been classified as a moderate severity vulnerability due to its potential to allow remote code execution through cross-site scripting.
To fix CVE-2012-0324, upgrade Jenkins to version 1.454 or later or update to Jenkins LTS 1.424.5 or later.
CVE-2012-0324 affects various versions of Jenkins, specifically those prior to versions 1.454, 1.424.5 for LTS, and 1.400.0.13 for Enterprise.
If exploited, CVE-2012-0324 can allow attackers to inject arbitrary web scripts or HTML into the web pages viewed by users.
Users of Jenkins versions below 1.454, including those using Jenkins LTS and Enterprise prior to specific patched releases, are primarily impacted by CVE-2012-0324.