← Back

CVE-2015-5326

nvd nist
Published: Nov 25, 2015Modified: May 6, 2026

JSON object

Loading...
4.3
Vector
AV:N/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 8.6 / Impact: 2.9
Source: NVD

Description

Cross-site scripting (XSS) vulnerability in the slave overview page in Jenkins before 1.638 and LTS before 1.625.2 allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the slave offline status message.

Affected (4)

1 product
Jenkins
1 product
Openshift
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.637
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 3.1
Configuration C
1 vulnerable
Vulnerable SoftwareAffected Versions
Version 2.0
Configuration D
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.625.1

References (6)

Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.