Vulnerability CVE-2017-17383


Published: 2017-12-06

Description:
Jenkins through 2.93 allows remote authenticated administrators to conduct XSS attacks via a crafted tool name in a job configuration form, as demonstrated by the JDK tool in Jenkins core and the Ant tool in the Ant plugin, aka SECURITY-624.

 References:
https://jenkins.io/security/advisory/2017-12-05/

Copyright 2017, cxsecurity.com

 

Back to Top