CVE-2017-2607 - CVE House
Back to Database
Status published Medium CVE-2017-2607

jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted...

Vulnerability Description

jenkins before versions 2.44, 2.32.2 is vulnerable to a persisted cross-site scripting vulnerability in console notes (SECURITY-382). Jenkins allows plugins to annotate build logs, adding new content or changing the presentation of existing content while the build is running. Malicious Jenkins users, or users with SCM access, could configure jobs or modify build scripts such that they print serialized console notes that perform cross-site scripting attacks on Jenkins users viewing the build logs.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2017-2607

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

jenkins
Vulnerable Versions:
jenkins 2.44, jenkins 2.32.2

Timeline

Official Publish: May 21st, 2018
Last Modified: August 5th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Weaknesses (CWE)