CVE-2018-1999005: XSS
A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in BuildTimelineWidget.java, BuildTimelineWidget/control.jelly that allows attackers with Job/Configure permission to define JavaScript that would be executed in another user's browser when that other user performs some UI actions.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1999005?
CVE-2018-1999005 is classified as a high severity vulnerability due to its potential for cross-site scripting attacks.
How do I fix CVE-2018-1999005?
To fix CVE-2018-1999005, update Jenkins to version 2.132 or later, or to 2.121.2.
What software is affected by CVE-2018-1999005?
CVE-2018-1999005 affects Jenkins versions 2.132 and earlier as well as version 2.121.1 and earlier.
What type of vulnerability is CVE-2018-1999005?
CVE-2018-1999005 is a cross-site scripting (XSS) vulnerability that allows attackers to execute JavaScript in another user's browser.
Who can exploit CVE-2018-1999005?
An attacker with Job/Configure permission can exploit CVE-2018-1999005 to execute scripts in the browsers of other users.