First published: Wed Jan 09 2019(Updated: )
A cross-site scripting vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/model/Api.java that allows attackers to specify URLs to Jenkins that result in rendering arbitrary attacker-controlled HTML by Jenkins.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Jenkins | <=2.138.1 | |
Jenkins Jenkins | <=2.145 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-1000407 is classified as a cross-site scripting vulnerability with a high severity rating.
To fix CVE-2018-1000407, update Jenkins to version 2.146 or later, or upgrade to the latest LTS version.
CVE-2018-1000407 affects Jenkins versions 2.145 and earlier, and LTS 2.138.1 and earlier.
CVE-2018-1000407 is a cross-site scripting (XSS) vulnerability.
No, CVE-2018-1000407 allows for the injection of arbitrary HTML but does not lead to remote code execution.