CVE-2012-4439: Jenkins
Medium severity, CVSS 6.1. EPSS: 1.8% chance of exploitation in the next 30 days.
Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL that points to Jenkins.
Affected products
- Jenkins Jenkins: before 1.466.2 (fixed in 1.466.2); before 1.482 (fixed in 1.482)
Published 2019-11-18. Last modified 2026-06-16.