Medium severity4.8NVD Advisory· Published Jan 26, 2018· Updated Jun 17, 2026
CVE-2017-1000392
CVE-2017-1000392
Description
Jenkins 2.88 and earlier; 2.73.2 and earlier Autocompletion suggestions for text fields were not escaped, resulting in a persisted cross-site scripting vulnerability if the source for the suggestions allowed specifying text that includes HTML metacharacters like less-than and greater-than characters.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.main:jenkins-coreMaven | < 2.73.3 | 2.73.3 |
org.jenkins-ci.main:jenkins-coreMaven | >= 2.74, < 2.89 | 2.89 |
Affected products
3cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:*+ 1 more
- cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:*range: <=2.88
- cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:*range: <=2.73.2
Patches
Vulnerability mechanics
References
7- www.securityfocus.com/bid/101773nvdThird Party AdvisoryVDB EntryWEB
- www.securityfocus.com/bid/102826nvdThird Party AdvisoryVDB EntryWEB
- github.com/advisories/GHSA-5ppx-rgw2-xg23ghsaADVISORY
- jenkins.io/security/advisory/2017-11-08/nvdVendor Advisory
- nvd.nist.gov/vuln/detail/CVE-2017-1000392ghsaADVISORY
- github.com/jenkinsci/jenkins/commit/f67068170b55633571e5462e52b6124b23d7cb84ghsaWEB
- jenkins.io/security/advisory/2017-11-08ghsaWEB
News mentions
0No linked articles in our index yet.