CVE-2012-0324: Cloudbees Jenkins
Medium severity, CVSS 4.3. EPSS: 1.1% chance of exploitation in the next 30 days.
Cross-site scripting (XSS) vulnerability in Jenkins before 1.454, Jenkins LTS before 1.424.5, and Jenkins Enterprise 1.400.x before 1.400.0.13 and 1.424.x before 1.424.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0325.
Affected products
- Cloudbees Jenkins: version 1.400 only; version 1.400.0.12 only; version 1.424 only; version 1.424.5 only; up to and including 1.453
- Jenkins Jenkins: version 1.301 only; version 1.302 only; version 1.303 only; version 1.304 only; version 1.305 only; version 1.306 only; …
Published 2012-03-09. Last modified 2026-06-16.