CVE-2018-1000407: XSS
Published Jan 9, 2019
·Updated
A cross-site scripting vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/model/Api.java that allows attackers to specify URLs to Jenkins that result in rendering arbitrary attacker-controlled HTML by Jenkins.
Affected Software
2 affected components
Jenkins Jenkins<=2.138.1
Jenkins Jenkins<=2.145
Event History
Jan 9, 2019
CVE Published
via MITRE·11:00 PM
Data Sourced
via MITRE·11:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-1000407?
CVE-2018-1000407 is classified as a cross-site scripting vulnerability with a high severity rating.
2
How do I fix CVE-2018-1000407?
To fix CVE-2018-1000407, update Jenkins to version 2.146 or later, or upgrade to the latest LTS version.
3
What versions of Jenkins are affected by CVE-2018-1000407?
CVE-2018-1000407 affects Jenkins versions 2.145 and earlier, and LTS 2.138.1 and earlier.
4
What type of vulnerability is CVE-2018-1000407?
CVE-2018-1000407 is a cross-site scripting (XSS) vulnerability.
5
Can CVE-2018-1000407 lead to remote code execution?
No, CVE-2018-1000407 allows for the injection of arbitrary HTML but does not lead to remote code execution.