CVE-2017-2601

medium

Description

Jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted cross-site scripting in parameter names and descriptions (SECURITY-353). Users with the permission to configure jobs were able to inject JavaScript into parameter names and descriptions.

References

https://github.com/advisories/GHSA-vf5v-6wjm-vr7v

https://github.com/advisories/GHSA-hqmp-vxj7-5wpq

https://github.com/advisories/GHSA-88r9-hfj2-54hv

https://github.com/advisories/GHSA-x95w-qf3m-pqpx

https://github.com/advisories/GHSA-pv38-mqpp-v72h

https://github.com/advisories/GHSA-pc9c-547w-hhmc

https://github.com/advisories/GHSA-jhfv-8936-g652

https://github.com/advisories/GHSA-hc44-p2qq-cfm9

https://github.com/advisories/GHSA-gpw4-7mcw-m8vx

https://github.com/advisories/GHSA-fcqr-gh8w-wm8f

https://github.com/advisories/GHSA-cqhr-q835-62gm

https://github.com/advisories/GHSA-7558-6q45-6x7m

https://github.com/advisories/GHSA-6923-546p-6rrc

https://github.com/advisories/GHSA-6882-385p-hhhw

https://github.com/advisories/GHSA-65r6-w7vr-c75r

https://github.com/advisories/GHSA-5hh2-f4h9-446g

https://github.com/advisories/GHSA-5247-whvj-83qw

https://github.com/advisories/GHSA-438w-rjj9-5fjf

https://github.com/advisories/GHSA-ppwv-mvqg-q89h

https://github.com/advisories/GHSA-mw4r-5mfc-m5vc

https://github.com/advisories/GHSA-h3v9-46pp-h33w

https://github.com/advisories/GHSA-9w23-w757-mvv8

https://github.com/advisories/GHSA-7rjv-q3pp-wc4p

https://github.com/advisories/GHSA-7j66-wvhr-m83x

https://github.com/advisories/GHSA-5pmp-7wc9-v7vw

https://github.com/advisories/GHSA-r69c-5j7c-vm6q

https://github.com/advisories/GHSA-455j-8hg5-8576

https://github.com/advisories/GHSA-wpr6-qvcq-8269

https://github.com/advisories/GHSA-pjm3-f4vh-3h3h

https://github.com/advisories/GHSA-m3p3-2gp6-ghq8

https://github.com/advisories/GHSA-f3jq-9c79-j65m

https://github.com/advisories/GHSA-v98r-gjgc-m9pf

https://github.com/advisories/GHSA-pv7p-c7cp-vrh3

https://jenkins.io/security/advisory/2017-02-01/

http://www.openwall.com/lists/oss-security/2022/10/19/3

Details

Source: Mitre, NVD

Published: 2018-05-10

Updated: 2026-06-17

Risk Information

CVSS v2

Base Score: 3.5

Vector: CVSS2#AV:N/AC:M/Au:S/C:N/I:P/A:N

Severity: Low

CVSS v3

Base Score: 5.4

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Severity: Medium

EPSS

EPSS: 0.00161