CVE-2015-1813: XSS
Published Oct 16, 2015
·Updated
Cross-site scripting (XSS) vulnerability in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-1812.
Affected Software
5 affected componentsFixes available
Jenkins Jenkins<=1.596.1
Jenkins Jenkins<=1.605
redhat Openshift<=3.1
maven/org.jenkins-ci.main:jenkins-core<1.596.2
1.596.2
maven/org.jenkins-ci.main:jenkins-core>=1.597<1.606
1.606
Event History
Oct 16, 2015
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
May 17, 2022
Advisory Published
via GitHub·03:53 AM
Frequently Asked Questions
1
What is the severity of CVE-2015-1813?
CVE-2015-1813 is classified as a medium severity vulnerability.
2
How do I fix CVE-2015-1813?
To fix CVE-2015-1813, upgrading Jenkins to version 1.606 or later is recommended.
3
Which versions of Jenkins are affected by CVE-2015-1813?
CVE-2015-1813 affects Jenkins versions before 1.606 and LTS versions before 1.596.2.
4
What type of vulnerability is CVE-2015-1813?
CVE-2015-1813 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2015-1813 lead to remote attacks?
Yes, CVE-2015-1813 allows remote attackers to inject arbitrary web scripts or HTML.