CVE-2017-1000392

Description

Jenkins 2.88 and earlier; 2.73.2 and earlier Autocompletion suggestions for text fields were not escaped, resulting in a persisted cross-site scripting vulnerability if the source for the suggestions allowed specifying text that includes HTML metacharacters like less-than and greater-than characters.

Risk Information

Base Score
4.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
EPSS Score
Exploitation Probability
0.155

Associated Vulnerability

VulnerabilityOS Platform
Multiple vulnerabilities affected in Jenkins 2.88Windows
Vulnerabilities CVE-2017-1000392,CVE-2017-1000391 are fixed in Jenkins-Core 2.73.3Windows
Vulnerabilities CVE-2017-1000392,CVE-2017-1000391 are fixed in Jenkins-Core 2.89Windows
Multiple vulnerabilities affected in Jenkins 2.88 (For Ubuntu)Linux
Multiple vulnerabilities affected in Jenkins 2.88 (For Debian)Linux
Multiple vulnerabilities affected in Jenkins 2.88 (For Centos)Linux
Multiple vulnerabilities affected in Jenkins 2.88 (For RedHat)Linux
Multiple vulnerabilities affected in Jenkins 2.88 (For Suse)Linux
Vulnerabilities CVE-2017-1000392,CVE-2017-1000391 are fixed in Jenkins-Core for Linux 2.73.3Linux
Vulnerabilities CVE-2017-1000392,CVE-2017-1000391 are fixed in Jenkins-Core for Linux 2.89Linux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234