CVE-2011-4344

low
Published 2011-12-01 · Modified 2025-03-13
CVSS v3
CVSS v2
2.6
VIR risk
2.6

Description

Jenkins allows Cross-Site Scripting (XSS)

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://github.com/jenkinsci/winstone/commit/410ed3001d51c689cf59085b7417466caa2ded7b.patch

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.cloudbees.com/jenkins-advisory/jenkins-security-advisory-2011-11-08.cb

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://openwall.com/lists/oss-security/2011/11/23/6

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://openwall.com/lists/oss-security/2011/11/23/5

Package impact

EcosystemPackageVulnerableFixed
java Mavenorg.jenkins-ci.main:jenkins-core<1.409.31.409.3
java Mavenorg.jenkins-ci.main:jenkins-core>=1.410,<1.4381.438

Application impact

VendorProductVersionsFixed
jenkinsjenkins1.409.1
jenkinsjenkins1.409.2
jenkinsjenkins{"endIncluding":"1.437"}

References

CWEs

CWE-79

Verify integrity in audit chain (admin only). AS-IS.