CVE-2017-1000392: Jenkins
Medium severity, CVSS 4.8. EPSS: 1.1% chance of exploitation in the next 30 days.
Jenkins 2.88 and earlier; 2.73.2 and earlier Autocompletion suggestions for text fields were not escaped, resulting in a persisted cross-site scripting vulnerability if the source for the suggestions allowed specifying text that includes HTML metacharacters like less-than and greater-than characters.
Affected products
- Jenkins Jenkins: up to and including 2.73.2; up to and including 2.88
Published 2018-01-26. Last modified 2026-06-17.