CVE-2017-17383: Jenkins
Medium severity, CVSS 4.7. EPSS: 1.2% chance of exploitation in the next 30 days.
Jenkins through 2.93 allows remote authenticated administrators to conduct XSS attacks via a crafted tool name in a job configuration form, as demonstrated by the JDK tool in Jenkins core and the Ant tool in the Ant plugin, aka SECURITY-624.
Affected products
- Jenkins Jenkins: up to and including 2.93
Published 2017-12-06. Last modified 2026-06-17.