← Back

CVE-2015-7536

nvd nist
Published: Feb 3, 2016Modified: May 6, 2026

JSON object

Loading...
5.4
Vector
CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.3 / Impact: 2.7
Source: NVD

Description

Cross-site scripting (XSS) vulnerability in Jenkins before 1.640 and LTS before 1.625.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors related to workspaces and archived artifacts.

Affected (2)

Products: Jenkins: Jenkins
1 product
Jenkins
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.625.1
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 1.639

References (2)

Timeline

No history available yet.