Persisted Cross-Site Scripting in Jenkins by CloudBees
CVE-2017-2607
4.2MEDIUM
What is CVE-2017-2607?
Jenkins, prior to versions 2.44 and 2.32.2, is susceptible to a persisted cross-site scripting vulnerability that mainly arises from its console notes feature. This allows users with malicious intent, including those with SCM access, to modify jobs or scripts to embed serialized console notes that can execute cross-site scripting attacks. When Jenkins users view the altered build logs, they may unknowingly execute harmful scripts, compromising the integrity and security of their environments.
Affected Version(s)
jenkins jenkins 2.44
jenkins jenkins 2.32.2
