CVE-2017-1000392

Publication date 26 January 2018

Last updated 17 July 2025


Ubuntu priority

Cvss 3 Severity Score

4.8 · Medium

Score breakdown

Description

Jenkins 2.88 and earlier; 2.73.2 and earlier Autocompletion suggestions for text fields were not escaped, resulting in a persisted cross-site scripting vulnerability if the source for the suggestions allowed specifying text that includes HTML metacharacters like less-than and greater-than characters.

Status

Package Ubuntu Release Status
jenkins 17.10 artful Not in release
17.04 zesty Not in release
16.04 LTS xenial Not in release
14.04 LTS trusty Not in release

Severity score breakdown

CVSS version: CVSS v3.0

Base score 4.8 · Medium

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N


Access our resources on patching vulnerabilities