CVE-2013-2033: XSS
Cross-site scripting (XSS) vulnerability in Jenkins before 1.514, LTS before 1.509.1, and Enterprise 1.466.x before 1.466.14.1 and 1.480.x before 1.480.4.1 allows remote authenticated users with write permission to inject arbitrary web script or HTML via unspecified vectors.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2033?
CVE-2013-2033 has a medium severity rating due to its potential to allow XSS attacks.
How do I fix CVE-2013-2033?
To fix CVE-2013-2033, upgrade Jenkins to version 1.514 or later, or applicable LTS and Enterprise versions.
Who is affected by CVE-2013-2033?
CVE-2013-2033 affects Jenkins installations prior to version 1.514, as well as specific CloudBees Enterprise versions.
What type of vulnerability is CVE-2013-2033?
CVE-2013-2033 is a cross-site scripting (XSS) vulnerability.
Can remote authenticated users exploit CVE-2013-2033?
Yes, remote authenticated users with write permissions can inject arbitrary web scripts or HTML through CVE-2013-2033.