Description
Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape notification bar response contents, resulting in a cross-site scripting (XSS) vulnerability.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2022-3324 | Jenkins 2.274 and earlier, LTS 2.263.1 and earlier does not escape notification bar response contents, resulting in a cross-site scripting (XSS) vulnerability. |
Github GHSA |
GHSA-98gq-6hxg-52r6 | XSS vulnerability in Jenkins notification bar |
References
History
No history.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2024-08-03T18:16:23.442Z
Reserved: 2021-01-04T00:00:00.000Z
Link: CVE-2021-21603
No data.
Status : Modified
Published: 2021-01-13T16:15:13.460
Modified: 2024-11-21T05:48:40.943
Link: CVE-2021-21603
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA