CVE-2014-2065

CVSS v2.0 4.3 (Medium)
43% Progress
EPSS 0.19 % (56th)
0.19% Progress
Affected Products 1
Advisories 1

Cross-site scripting (XSS) vulnerability in Jenkins before 1.551 and LTS before 1.532.2 allows remote attackers to inject arbitrary web script or HTML via the iconSize cookie.

Weaknesses
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE Status
PUBLISHED
CNA
Debian GNU/Linux
Published Date
2014-10-17 15:55:05
(10 years ago)
Updated Date
2016-06-13 23:39:15
(8 years ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Jenkins 1.532.1 and prior versions cpe:2.3:a:jenkins:jenkins::*:*:*:lts <= 1.532.1

Configuration #2

    CPE23 From Up To
  Jenkins 1.550 and prior versions cpe:2.3:a:jenkins:jenkins <= 1.550
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...