A cross-site scripting vulnerability exists in Jenkins 2.145 and previous versions, LTS 2.138.1 and previous versions in core/src/main/java/hudson/model/Api.java that allows malicious users to specify URLs to Jenkins that result in rendering arbitrary attacker-controlled HTML by Jenkins.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
jenkins jenkins |