CVE-2017-17383: XSS
Jenkins through 2.93 allows remote authenticated administrators to conduct XSS attacks via a crafted tool name in a job configuration form, as demonstrated by the JDK tool in Jenkins core and the Ant tool in the Ant plugin, aka SECURITY-624.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-17383?
CVE-2017-17383 has a medium severity level due to potential XSS vulnerabilities that can affect authenticated administrators.
How do I fix CVE-2017-17383?
To fix CVE-2017-17383, update Jenkins to a version later than 2.93 to eliminate the vulnerability.
Who is affected by CVE-2017-17383?
CVE-2017-17383 affects authenticated administrators using Jenkins versions up to and including 2.93.
What types of attacks can be executed through CVE-2017-17383?
CVE-2017-17383 allows for cross-site scripting (XSS) attacks through crafted tool names in job configuration forms.
What components of Jenkins are impacted by CVE-2017-17383?
CVE-2017-17383 affects Jenkins core and certain plugins, including the JDK tool and the Ant tool.