CVE-2018-1999005
23.07.2018, 19:29
A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in BuildTimelineWidget.java, BuildTimelineWidget/control.jelly that allows attackers with Job/Configure permission to define JavaScript that would be executed in another user's browser when that other user performs some UI actions.
Vendor | Product | Version |
---|---|---|
jenkins | jenkins | 𝑥 ≤ 2.121.1 |
jenkins | jenkins | 2.122 ≤ 𝑥 ≤ 2.132 |
oracle | communications_cloud_native_core_automated_test_suite | 1.9.0 |
𝑥
= Vulnerable software versions