Total vulnerabilities in the database
Jenkins 2.227 and earlier, LTS 2.204.5 and earlier does not set Content-Security-Policy headers for files uploaded as file parameters to a build, resulting in a stored XSS vulnerability.
Software | From | Fixed in |
---|---|---|
jenkins / jenkins | - | 2.204.5.x |
jenkins / jenkins | - | 2.227.x |
![]() |
- | 2.228 |
![]() |
2.204.6 | 2.228 |