First published: Thu Apr 10 2014(Updated: )
Cross-site scripting (XSS) vulnerability in Jenkins before 1.514, LTS before 1.509.1, and Enterprise 1.466.x before 1.466.14.1 and 1.480.x before 1.480.4.1 allows remote authenticated users with write permission to inject arbitrary web script or HTML via unspecified vectors.
Credit: secalert@redhat.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Jenkins | <1.509.1 | |
Jenkins Jenkins | <1.514 | |
Cloudbees Jenkins | >=1.466<1.466.14.1 | |
Cloudbees Jenkins | >=1.480<1.480.4.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-2033 has a medium severity rating due to its potential to allow XSS attacks.
To fix CVE-2013-2033, upgrade Jenkins to version 1.514 or later, or applicable LTS and Enterprise versions.
CVE-2013-2033 affects Jenkins installations prior to version 1.514, as well as specific CloudBees Enterprise versions.
CVE-2013-2033 is a cross-site scripting (XSS) vulnerability.
Yes, remote authenticated users with write permissions can inject arbitrary web scripts or HTML through CVE-2013-2033.