Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2017-2601

Jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted cross-site scripting in parameter names and descriptions (SECURITY-353). Users with the permission to configure jobs were able to inject JavaScript into parameter names and descriptions.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 37.9%
CVSS Severity
CVSS v3 Score 6.1
CVSS v2 Score 3.5
References
Products affected by CVE-2017-2601


Contact Us

Shodan ® - All rights reserved