Jenkins through 2.93 allows remote authenticated administrators to conduct XSS attacks via a crafted tool name in a job configuration form, as demonstrated by the JDK tool in Jenkins core and the Ant tool in the Ant plugin, aka SECURITY-624.
2017-12-06T05:29:00.270
2025-04-20T01:37:25.860
Deferred
CVSSv3.0: 4.7 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9