Security Advisory

CVE-2018-1000170

5.4
MEDIUM

Vulnerability Description

A cross-site scripting vulnerability exists in Jenkins 2.115 and older, LTS 2.107.1 and older, in confirmationList.jelly and stopButton.jelly that allows attackers with Job/Configure and/or Job/Create permission to create an item name containing JavaScript that would be executed in another user's browser when that other user performs some UI actions.
Published Date April 16, 2018
Official Source NIST NVD Advisory