CVE-2015-5326: XSS
Cross-site scripting (XSS) vulnerability in the slave overview page in Jenkins before 1.638 and LTS before 1.625.2 allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the slave offline status message.
Other sources
The following flaw was found in Jenkins:
Users with the permission to take slave nodes offline can enter arbitrary HTML that gets shown unescaped to users visiting the slave overview page.
This flaw allows admins and users with significant privileges to circumvent XSS protection.
External References:
https://wiki.jenkins-ci.org/display/SECURITY/Jenkins+Security+Advisory+2015-11-11
— Red Hat
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-5326?
CVE-2015-5326 is rated as a moderate severity vulnerability.
How do I fix CVE-2015-5326?
To fix CVE-2015-5326, upgrade Jenkins to version 1.638 or later, or LTS to 1.625.2 or later.
What type of vulnerability is CVE-2015-5326?
CVE-2015-5326 is a cross-site scripting (XSS) vulnerability.
Who is affected by CVE-2015-5326?
CVE-2015-5326 affects remote authenticated users with specific permissions in Jenkins.
What specific software versions are affected by CVE-2015-5326?
CVE-2015-5326 affects Jenkins versions before 1.638 and LTS versions before 1.625.2.