First published: Wed Dec 06 2017(Updated: )
Jenkins through 2.93 allows remote authenticated administrators to conduct XSS attacks via a crafted tool name in a job configuration form, as demonstrated by the JDK tool in Jenkins core and the Ant tool in the Ant plugin, aka SECURITY-624.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins LTS | <=2.93 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-17383 has a medium severity level due to potential XSS vulnerabilities that can affect authenticated administrators.
To fix CVE-2017-17383, update Jenkins to a version later than 2.93 to eliminate the vulnerability.
CVE-2017-17383 affects authenticated administrators using Jenkins versions up to and including 2.93.
CVE-2017-17383 allows for cross-site scripting (XSS) attacks through crafted tool names in job configuration forms.
CVE-2017-17383 affects Jenkins core and certain plugins, including the JDK tool and the Ant tool.