← Back

CVE-2012-6074

nvd nist
Published: Feb 24, 2013Modified: Apr 29, 2026

JSON object

Loading...
3.5
Vector
AV:N/AC:M/Au:S/C:N/I:P/A:N
Exploitability: 6.8 / Impact: 2.9
Source: NVD

Description

Cross-site scripting (XSS) vulnerability in Jenkins before 1.491, Jenkins LTS before 1.480.1, and Jenkins Enterprise 1.424.x before 1.424.6.13, 1.447.x before 1.447.4.1, and 1.466.x before 1.466.10.1 allows remote authenticated users with write access to inject arbitrary web script or HTML via unspecified vectors.

Affected (68)

1 product
Jenkins
1 product
Jenkins
Configuration A
39 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.480.3.1
Jenkins
Version 1.400
Version 1.401
Version 1.402
Version 1.403
Version 1.404
Version 1.405
Version 1.406
Version 1.407
Version 1.408
Version 1.409
Version 1.410
Version 1.411
Version 1.412
Version 1.413
Version 1.414
Version 1.415
Version 1.416
Version 1.417
Version 1.418
Version 1.419
Version 1.420
Version 1.421
Version 1.422
Version 1.423
Version 1.424
Version 1.425
Version 1.426
Version 1.427
Version 1.428
Version 1.429
Version 1.430
Version 1.431
Version 1.432
Version 1.433
Version 1.434
Version 1.435
Version 1.436
Version 1.437
Configuration B
3 vulnerable
Vulnerable SoftwareAffected Versions
Cloudbees
Version 1.447.1.1
Version 1.447.2.2
Version 1.447.3.1
Configuration C
8 vulnerable
Vulnerable SoftwareAffected Versions
Cloudbees
Version 1.424.0.2
Version 1.424.0.4
Version 1.424.1.1
Version 1.424.2.1
Version 1.424.4.1
Version 1.424.5.1
Version 1.424.6.11
Version 1.424.6.1
Configuration D
2 vulnerable
Vulnerable SoftwareAffected Versions
Cloudbees
Version 1.466.1.2
Version 1.466.2.1
Configuration E
16 vulnerable
Vulnerable SoftwareAffected Versions
Cloudbees
Version 1.400
Version 1.424
Version 1.447
Jenkins
Up to 1.466.2
Version 1.409.1
Version 1.409.2
Version 1.409.3
Version 1.424.1
Version 1.424.2
Version 1.424.3
Version 1.424.4
Version 1.424.5
Version 1.424.6
Version 1.447.1
Version 1.447.2
Version 1.466.1

Timeline

No history available yet.