An open API service providing security vulnerability metadata for many open source software ecosystems.

GSA_kwCzR0hTQS1nOHBnLXFydm0td2doMs4AAkDM

Moderate EPSS: 0.00303% (0.53139 Percentile) EPSS:

Improper Neutralization of Input During Web Page Generation in Jenkins

Affected Packages Affected Versions Fixed Versions
maven:org.jenkins-ci.main:jenkins-core > 2.222.1, <= 2.227, <= 2.204.5 2.228, 2.204.6

Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not properly escape node labels that are shown in the form validation for label expressions on job configuration pages, resulting in a stored XSS vulnerability exploitable by users able to define node labels.

References: