CVE-2013-2033

CVSS v2.0 2.1 (Low)
21% Progress
EPSS 0.09 % (38th)
0.09% Progress
Affected Products 2
Advisories 2

Cross-site scripting (XSS) vulnerability in Jenkins before 1.514, LTS before 1.509.1, and Enterprise 1.466.x before 1.466.14.1 and 1.480.x before 1.480.4.1 allows remote authenticated users with write permission to inject arbitrary web script or HTML via unspecified vectors.

Weaknesses
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2014-04-10 20:29:20
(10 years ago)
Updated Date
2023-02-13 04:42:42
(19 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Jenkins prior 1.509.1 version cpe:2.3:a:jenkins:jenkins::*:*:*:lts < 1.509.1
  Jenkins prior 1.514 version cpe:2.3:a:jenkins:jenkins < 1.514

Configuration #2

    CPE23 From Up To
  Cloudbees Jenkins from 1.466 version and prior 1.466.14.1 version cpe:2.3:a:cloudbees:jenkins::*:*:*:enterprise >= 1.466 < 1.466.14.1
  Cloudbees Jenkins from 1.480 version and prior 1.480.4.1 version cpe:2.3:a:cloudbees:jenkins::*:*:*:enterprise >= 1.480 < 1.480.4.1
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...