Medium severity5.4NVD Advisory· Published Jul 23, 2018· Updated Jun 17, 2026
CVE-2018-1999007
CVE-2018-1999007
Description
A cross-site scripting vulnerability exists in Jenkins 2.132 and earlier, 2.121.1 and earlier in the Stapler web framework's org/kohsuke/stapler/Stapler.java that allows attackers with the ability to control the existence of some URLs in Jenkins to define JavaScript that would be executed in another user's browser when that other user views HTTP 404 error pages while Stapler debug mode is enabled.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.main:jenkins-coreMaven | < 2.121.2 | 2.121.2 |
org.jenkins-ci.main:jenkins-coreMaven | >= 2.122, < 2.132 | 2.132 |
org.kohsuke.stapler:stapler-parentMaven | < 1.250.1 | 1.250.1 |
Affected products
4- cpe:2.3:a:oracle:communications_cloud_native_core_automated_test_suite:1.9.0:*:*:*:*:*:*:*
- ghsa-coords2 versions
< 2.121.2+ 1 more
- (no CPE)range: < 2.121.2
- (no CPE)range: < 1.250.1
Patches
Vulnerability mechanics
References
5- www.oracle.com/security-alerts/cpuapr2022.htmlnvdPatchThird Party AdvisoryWEB
- github.com/advisories/GHSA-6456-xjm5-g3pgghsaADVISORY
- jenkins.io/security/advisory/2018-07-18/nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2018-1999007ghsaADVISORY
- github.com/jenkinsci/stapler/commit/03e221a81e8424709d1fbdf72ab814309dd8e13fghsaWEB
News mentions
0No linked articles in our index yet.