CVE-2013-0328: CSRF
Cross-site scripting (XSS) vulnerability in Jenkins before 1.502 and LTS before 1.480.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Other sources
Jenkins Security Advisory 2013-02-16
Another vulnerability enables cross-site scripting (XSS) attacks.
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2013-02-16
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0328?
CVE-2013-0328 is classified as a medium-severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2013-0328?
To fix CVE-2013-0328, upgrade Jenkins to version 1.502 or later.
What versions of Jenkins are affected by CVE-2013-0328?
Jenkins versions prior to 1.502 and LTS versions prior to 1.480.3 are affected by CVE-2013-0328.
What type of vulnerability is CVE-2013-0328?
CVE-2013-0328 is a cross-site scripting (XSS) vulnerability that allows remote attackers to inject arbitrary web scripts or HTML.
Is there a known exploit for CVE-2013-0328?
While there is no specific exploit publicly documented for CVE-2013-0328, it represents a significant risk due to the nature of XSS vulnerabilities.