A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in BuildTimelineWidget.java, BuildTimelineWidget/control.jelly that allows attackers with Job/Configure permission to define JavaScript that would be executed in another user's browser when that other user performs some UI actions.
2018-07-23T19:29:00.423
2024-11-21T03:57:01.673
Modified
CVSSv3.1: 5.4 (MEDIUM)
AV:N/AC:M/Au:S/C:N/I:P/A:N
6.8
2.9
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | jenkins | jenkins | ≤ 2.121.1 | Yes |
| Application | jenkins | jenkins | ≤ 2.132 | Yes |
| Application | oracle | communications_cloud_native_core_automated_test_suite | 1.9.0 | Yes |