Related Vulnerabilities: CVE-2017-17383  

Jenkins through 2.93 allows remote authenticated administrators to conduct XSS attacks via a crafted tool name in a job configuration form, as demonstrated by the JDK tool in Jenkins core and the Ant tool in the Ant plugin, aka SECURITY-624.

Severity Medium

Remote Yes

Type Cross-site scripting

Description

Jenkins through 2.93 allows remote authenticated administrators to conduct XSS attacks via a crafted tool name in a job configuration form, as demonstrated by the JDK tool in Jenkins core and the Ant tool in the Ant plugin, aka SECURITY-624.

AVG-543 jenkins 2.93-1 2.94-1 Medium Fixed

https://jenkins.io/security/advisory/2017-12-05/