CVE-2017-17383
06.12.2017, 05:29
Jenkins through 2.93 allows remote authenticated administrators to conduct XSS attacks via a crafted tool name in a job configuration form, as demonstrated by the JDK tool in Jenkins core and the Ant tool in the Ant plugin, aka SECURITY-624.
Vendor | Product | Version |
---|---|---|
jenkins | jenkins | 𝑥 ≤ 2.93 |
𝑥
= Vulnerable software versions
References