First published: Mon Nov 18 2019(Updated: )
Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL that points to Jenkins.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
debian/jenkins | ||
Jenkins LTS | <1.466.2 | |
Jenkins LTS | <1.482 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2012-4439 is classified as a medium severity vulnerability due to its potential for remote exploitation.
To fix CVE-2012-4439, update Jenkins to version 1.482 or later, or to LTS version 1.466.2 or later.
CVE-2012-4439 involves Cross-site Scripting (XSS), allowing attackers to inject arbitrary web scripts.
Jenkins versions before 1.482 and LTS versions before 1.466.2 are affected by CVE-2012-4439.
Yes, CVE-2012-4439 can be exploited remotely through a crafted URL pointing to Jenkins.