CVE-2012-4440: Jenkins
Medium severity, CVSS 6.1. EPSS: 1.9% chance of exploitation in the next 30 days.
Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the Violations plugin.
Affected products
- Jenkins Jenkins: before 1.466.2 (fixed in 1.466.2); before 1.482 (fixed in 1.482)
Published 2019-11-18. Last modified 2026-06-16.