CVE-2018-1000170

medium

Description

A cross-site scripting vulnerability exists in Jenkins 2.115 and older, LTS 2.107.1 and older, in confirmationList.jelly and stopButton.jelly that allows attackers with Job/Configure and/or Job/Create permission to create an item name containing JavaScript that would be executed in another user's browser when that other user performs some UI actions.

References

https://github.com/advisories/GHSA-9jcv-v4jp-w3cq

https://jenkins.io/security/advisory/2018-04-11/#SECURITY-759

https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-3401

Details

Source: Mitre, NVD

Published: 2018-04-16

Updated: 2026-06-17

Risk Information

CVSS v2

Base Score: 3.5

Vector: CVSS2#AV:N/AC:M/Au:S/C:N/I:P/A:N

Severity: Low

CVSS v3

Base Score: 5.4

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

Severity: Medium

EPSS

EPSS: 0.00867