CVE-2011-4344

Severity CVSS v4.0:
Pending analysis
Type:
CWE-79 Cross-Site Scripting (XSS)
Publication date:
01/12/2011
Last modified:
11/04/2025

Description

Cross-site scripting (XSS) vulnerability in Jenkins Core in Jenkins before 1.438, and 1.409 LTS before 1.409.3 LTS, when a stand-alone container is used, allows remote attackers to inject arbitrary web script or HTML via vectors related to error messages.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jenkins:jenkins:1.409.1:*:*:*:lts:*:*:*
cpe:2.3:a:jenkins:jenkins:1.409.2:*:*:*:lts:*:*:*
cpe:2.3:a:jenkins:jenkins:*:*:*:*:*:*:*:* 1.437 (including)