Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not properly escape node labels that are shown in the form validation for label expressions on job configuration pages, resulting in a stored XSS vulnerability exploitable by users able to define node labels.
| Software | From | Fixed in |
|---|---|---|
| jenkins / jenkins | - | 2.204.5.x |
| jenkins / jenkins | - | 2.227.x |
org.jenkins-ci.main / jenkins-core
|
- | 2.228 |
org.jenkins-ci.main / jenkins-core
|
2.204.6 | 2.228 |