Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-53441

Опубликовано: 10 июн. 2026
Источник: redhat
CVSS3: 5.4

Описание

Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not escape the user-provided description of a generic offline cause that could be set through the POST config.xml API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.

A flaw was found in Jenkins. This vulnerability, a stored cross-site scripting (XSS) issue, allows attackers with Agent/Configure permission to inject malicious scripts into the user-provided description of a generic offline cause. When other users view this description, the injected script can execute in their browser, potentially leading to information disclosure or unauthorized actions.

Меры по смягчению последствий

To fully mitigate this vulnerability, upgrade the Jenkins instance to version 2.568 or LTS 2.555.3 (or later). These releases officially resolve the issue by securely rendering the offline cause descriptions as plain text. If an immediate upgrade is not feasible, the risk can be significantly reduced by auditing Role-Based Access Control (RBAC) settings and strictly limiting the Agent/Configure permission to highly trusted, essential administrators only.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
OpenShift Developer Tools and ServicesjenkinsFix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-79
https://bugzilla.redhat.com/show_bug.cgi?id=2487533jenkins: Jenkins: Stored Cross-Site Scripting (XSS) via unescaped user-provided description

5.4 Medium

CVSS3

Связанные уязвимости

CVSS3: 5.4
nvd
около 2 месяцев назад

Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not escape the user-provided description of a generic offline cause that could be set through the `POST config.xml` API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.

CVSS3: 8
github
около 2 месяцев назад

Jenkins: Stored XSS vulnerability in node offline cause description

5.4 Medium

CVSS3