CVE-2012-4439

Publication date 18 November 2019

Last updated 25 August 2025


Ubuntu priority

Cvss 3 Severity Score

6.1 · Medium

Score breakdown

Description

Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL that points to Jenkins.

Status

Package Ubuntu Release Status
jenkins 13.04 raring
Not affected
12.10 quantal
Not affected
12.04 LTS precise
Fixed 1.424.6+dfsg-1ubuntu0.1
11.10 oneiric Ignored end of life
11.04 natty Not in release
10.04 LTS lucid Not in release
8.04 LTS hardy Not in release

Severity score breakdown

CVSS version: CVSS v3.0

Base score 6.1 · Medium

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N


Access our resources on patching vulnerabilities