CVE-2017-17383

Source
Severity Medium
Remote Yes
Type Cross-site scripting
Description
Jenkins through 2.93 allows remote authenticated administrators to conduct XSS attacks via a crafted tool name in a job configuration form, as demonstrated by the JDK tool in Jenkins core and the Ant tool in the Ant plugin, aka SECURITY-624.
Group Package Affected Fixed Severity Status Ticket
AVG-543 jenkins 2.93-1 Medium Vulnerable
References
https://jenkins.io/security/advisory/2017-12-05/