CVE-2017-17383: Jenkins

Medium severity, CVSS 4.7. EPSS: 1.2% chance of exploitation in the next 30 days.

Jenkins through 2.93 allows remote authenticated administrators to conduct XSS attacks via a crafted tool name in a job configuration form, as demonstrated by the JDK tool in Jenkins core and the Ant tool in the Ant plugin, aka SECURITY-624.

Affected products

  • Jenkins Jenkins: up to and including 2.93

Published 2017-12-06. Last modified 2026-06-17.