Cross-site scripting in Jenkins - CVE-2017-2607
Published: May 22, 2018 / Updated: July 17, 2020
Jenkins
Detailed vulnerability description
The disclosed vulnerability allows a remote attacker to perform cross-site scripting (XSS) attacks.
The vulnerability exists due to insufficient sanitization of user-supplied data. The vulnerability allows plugins to annotate build logs, adding new content or changing the presentation of existing content while the build is running.
Successful exploitation of this vulnerability may allow a remote attacker to steal potentially sensitive information, change appearance of the web page, perform phishing and drive-by-download attacks.