CVE-2013-2033: Cloudbees Jenkins
Low severity, CVSS 2.1. EPSS: 1.9% chance of exploitation in the next 30 days.
Cross-site scripting (XSS) vulnerability in Jenkins before 1.514, LTS before 1.509.1, and Enterprise 1.466.x before 1.466.14.1 and 1.480.x before 1.480.4.1 allows remote authenticated users with write permission to inject arbitrary web script or HTML via unspecified vectors.
Affected products
- Cloudbees Jenkins: from 1.466, before 1.466.14.1 (fixed in 1.466.14.1); from 1.480, before 1.480.4.1 (fixed in 1.480.4.1)
- Jenkins Jenkins: before 1.509.1 (fixed in 1.509.1); before 1.514 (fixed in 1.514)
Published 2014-04-10. Last modified 2026-06-16.