← Back

CVE-2012-0324

nvd nist
Published: Mar 9, 2012Modified: Apr 29, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Cross-site scripting (XSS) vulnerability in Jenkins before 1.454, Jenkins LTS before 1.424.5, and Jenkins Enterprise 1.400.x before 1.400.0.13 and 1.424.x before 1.424.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0325.

Affected (144)

1 product
Jenkins
1 product
Jenkins
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
Cloudbees
Version 1.400.0.12
Version 1.400
Version 1.424.5
Version 1.424
Configuration B
2 vulnerable
Vulnerable SoftwareAffected Versions
Cloudbees
Version 1.400.0.12
Version 1.400
Configuration C
138 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.453
Jenkins
Version 1.301
Version 1.302
Version 1.303
Version 1.304
Version 1.305
Version 1.306
Version 1.307
Version 1.308
Version 1.309
Version 1.310
Version 1.311
Version 1.312
Version 1.313
Version 1.314
Version 1.315
Version 1.316
Version 1.317
Version 1.318
Version 1.319
Version 1.320
Version 1.321
Version 1.322
Version 1.323
Version 1.324
Version 1.325
Version 1.326
Version 1.327
Version 1.328
Version 1.329
Version 1.330
Version 1.331
Version 1.332
Version 1.333
Version 1.334
Version 1.335
Version 1.336
Version 1.337
Version 1.338
Version 1.339
Version 1.340
Version 1.341
Version 1.342
Version 1.343
Version 1.344
Version 1.345
Version 1.346
Version 1.347
Version 1.348
Version 1.349
Version 1.350
Version 1.351
Version 1.352
Version 1.353
Version 1.354
Version 1.355
Version 1.356
Version 1.357
Version 1.358
Version 1.359
Version 1.360
Version 1.361
Version 1.362
Version 1.363
Version 1.364
Version 1.365
Version 1.366
Version 1.367
Version 1.368
Version 1.369
Version 1.370
Version 1.371
Version 1.372
Version 1.373
Version 1.374
Version 1.375
Version 1.376
Version 1.377
Version 1.378
Version 1.379
Version 1.380
Version 1.382
Version 1.383
Version 1.384
Version 1.386
Version 1.387
Version 1.388
Version 1.389
Version 1.390
Version 1.391
Version 1.392
Version 1.393
Version 1.394
Version 1.395
Version 1.396
Version 1.397
Version 1.398
Version 1.399
Version 1.400
Version 1.401
Version 1.402
Version 1.403
Version 1.404
Version 1.405
Version 1.406
Version 1.407
Version 1.408
Version 1.409.1
Version 1.409.2
Version 1.409
Version 1.410
Version 1.411
Version 1.412
Version 1.413
Version 1.414
Version 1.415
Version 1.416
Version 1.417
Version 1.418
Version 1.419
Version 1.420
Version 1.421
Version 1.422
Version 1.423
Version 1.424
Version 1.425
Version 1.426
Version 1.427
Version 1.428
Version 1.429
Version 1.430
Version 1.431
Version 1.432
Version 1.433
Version 1.434
Version 1.435
Version 1.436
Version 1.437

References (8)

Source: vultures@jpcert.or.jp
Source: vultures@jpcert.or.jp
Source: vultures@jpcert.or.jp
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.