2.6
CVSSv2

CVE-2011-4344

Published: 01/12/2011 Updated: 13/06/2016
CVSS v2 Base Score: 2.6 | Impact Score: 2.9 | Exploitability Score: 4.9
VMScore: 231
Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N

Vulnerability Summary

Cross-site scripting (XSS) vulnerability in Jenkins Core in Jenkins prior to 1.438, and 1.409 LTS prior to 1.409.3 LTS, when a stand-alone container is used, allows remote malicious users to inject arbitrary web script or HTML via vectors related to error messages.

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins jenkins 1.409.1

jenkins jenkins 1.409.2

jenkins jenkins

Vendor Advisories

Debian Bug report logs - #649900 CVE-2011-4344: XSS Package: jenkins-winstone; Maintainer for jenkins-winstone is Debian Java Maintainers <pkg-java-maintainers@listsaliothdebianorg>; Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Thu, 24 Nov 2011 17:15:01 UTC Severity: grave Tags: security Fixed in versio ...