Security Advisory
CVE-2018-1000170
5.4
MEDIUM
Vulnerability Description
A cross-site scripting vulnerability exists in Jenkins 2.115 and older, LTS 2.107.1 and older, in confirmationList.jelly and stopButton.jelly that allows attackers with Job/Configure and/or Job/Create permission to create an item name containing JavaScript that would be executed in another user's browser when that other user performs some UI actions.
Published Date
April 16, 2018
Official Source
NIST NVD Advisory