Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-27099

Опубликовано: 18 фев. 2026
Источник: redhat
CVSS3: 4.6
EPSS Низкий

Описание

Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-provided description of the "Mark temporarily offline" offline cause, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure or Agent/Disconnect permission.

A flaw was found in Jenkins. This vulnerability, identified as a stored cross-site scripting (XSS) issue, occurs because Jenkins does not properly escape the user-provided description for the "Mark temporarily offline" cause. An attacker with Agent/Configure or Agent/Disconnect permissions can exploit this to inject malicious scripts, leading to potential information disclosure or unauthorized actions within the user's browser.

Отчет

This vulnerability in Jenkins allows authenticated attackers with Agent/Configure or Agent/Disconnect permissions to inject malicious scripts into the "Mark temporarily offline" cause description. This stored cross-site scripting (XSS) flaw can lead to information disclosure or unauthorized actions within a user's browser when viewing the affected description. Red Hat OpenShift Developer Tools & Services are affected.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and ServicesjenkinsFix deferred
OpenShift Developer Tools and Services 4.12ocp-tools-4/jenkins-rhel8FixedRHSA-2026:1020923.04.2026
OpenShift Developer Tools and Services 4.13ocp-tools-4/jenkins-rhel8FixedRHSA-2026:1020123.04.2026
OpenShift Developer Tools and Services 4.14ocp-tools-4/jenkins-rhel8FixedRHSA-2026:1021123.04.2026
OpenShift Developer Tools and Services 4.15ocp-tools-4/jenkins-rhel8FixedRHSA-2026:1020423.04.2026
OpenShift Developer Tools and Services 4.16ocp-tools-4/jenkins-rhel9FixedRHSA-2026:1021423.04.2026
OpenShift Developer Tools and Services 4.17ocp-tools-4/jenkins-rhel9FixedRHSA-2026:1021323.04.2026
OpenShift Developer Tools and Services 4.18ocp-tools-4/jenkins-rhel9FixedRHSA-2026:1021523.04.2026
OpenShift Developer Tools and Services 4.19ocp-tools-4/jenkins-rhel9FixedRHSA-2026:1020623.04.2026
OpenShift Developer Tools and Services 4.2ocp-tools-4/jenkins-rhel9FixedRHSA-2026:1020523.04.2026

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2440638org.jenkins-ci.main/jenkins-core: Jenkins: Stored Cross-site Scripting (XSS) via unescaped user-provided offline cause description

EPSS

Процентиль: 40%
0.00505
Низкий

4.6 Medium

CVSS3

Связанные уязвимости

CVSS3: 8
nvd
6 месяцев назад

Jenkins 2.483 through 2.550 (both inclusive), LTS 2.492.1 through 2.541.1 (both inclusive) does not escape the user-provided description of the "Mark temporarily offline" offline cause, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure or Agent/Disconnect permission.

CVSS3: 8
github
6 месяцев назад

Jenkins has a stored XSS vulnerability in node offline cause description

CVSS3: 8
fstec
6 месяцев назад

Уязвимость сервера автоматизации Jenkins связана с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю выполнить произвольный код

CVSS3: 8
redos
5 месяцев назад

Уязвимость jenkins

EPSS

Процентиль: 40%
0.00505
Низкий

4.6 Medium

CVSS3