Total vulnerabilities in the database
Jenkins 2.367 through 2.369 (both inclusive) does not escape tooltips of the l:helpIcon UI component used for some help icons on the Jenkins web UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control tooltips for this component.
Software | From | Fixed in |
---|---|---|
![]() |
2.367 | 2.370 |
jenkins / jenkins | 2.367 | 2.370 |