Mission and Overview
NVD is the U.S. government repository of standards based vulnerability management data. This data enables automation of vulnerability management, security measurement, and compliance (e.g. FISMA).
Resource Status
NVD contains:
CVE Vulnerabilities
56428
Checklists
221
US-CERT Alerts
246
US-CERT Vuln Notes
2721
OVAL Queries
8140
CPE Names
73307

Last updated: Fri May 24 05:24:17 EDT 2013

CVE Publication rate: 12.5

Email List

NVD provides four mailing lists to the public. For information and subscription instructions please visit NVD Mailing Lists

Workload Index

Vulnerability Workload Index: 6.48

About Us
NVD is a product of the NIST Computer Security Division and is sponsored by the Department of Homeland Security's National Cyber Security Division. It supports the U.S. government multi-agency (OSD, DHS, NSA, DISA, and NIST) Information Security Automation Program. It is the U.S. government content repository for the Security Content Automation Protocol (SCAP).

National Cyber Awareness System

Vulnerability Summary for CVE-2012-0325

Original release date:03/09/2012
Last revised:03/11/2012
Source: US-CERT/NIST

Overview

Cross-site scripting (XSS) vulnerability in CloudBees Jenkins before 1.454, Jenkins LTS before 1.424.5, and Jenkins Enterprise 1.400.x before 1.400.0.13 and 1.424.x before 1.424.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0324.

Impact

CVSS Severity (version 2.0):
CVSS v2 Base Score:4.3 (MEDIUM) (AV:N/AC:M/Au:N/C:N/I:P/A:N) (legend)
Impact Subscore: 2.9
Exploitability Subscore: 8.6
CVSS Version 2 Metrics:
Access Vector: Network exploitable; Victim must voluntarily interact with attack mechanism
Access Complexity: Medium
Authentication: Not required to exploit
Impact Type:Allows unauthorized modification

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to nvd@nist.gov.

External Source: CONFIRM
Name: http://www.cloudbees.com/jenkins-advisory/jenkins-security-advisory-2012-03-05.cb
Type: Advisory
External Source: JVNDB
Name: JVNDB-2012-000023
External Source: JVN
Name: JVN#79950061

Vulnerable software and versions

Nav control imageConfiguration 1
line trunkNav control imageOR
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.453 and previous versions
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.409.2::lts
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.409.1::lts
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.404
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.403
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.431
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.430
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.433
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.432
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.427
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.426
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.429
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.428
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.423
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.422
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.425
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.424
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.419
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.418
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.421
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.420
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.414
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.415
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.416
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.417
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.410
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.411
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.412
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.413
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.406
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.407
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.408
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.409
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.405
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.436
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.437
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.434
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.435
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.301
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.302
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.303
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.308
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.309
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.310
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.311
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.304
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.305
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.306
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.307
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.334
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.335
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.332
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.333
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.330
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.331
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.328
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.329
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.342
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.343
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.340
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.341
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.338
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.339
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.336
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.337
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.319
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.318
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.317
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.316
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.315
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.314
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.313
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.312
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.327
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.326
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.325
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.324
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.323
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.322
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.321
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.320
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.360
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.361
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.362
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.363
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.364
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.365
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.366
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.367
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.368
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.369
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.370
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.371
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.372
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.373
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.374
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.375
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.345
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.344
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.347
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.346
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.349
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.348
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.351
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.350
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.353
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.352
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.355
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.354
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.357
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.356
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.359
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.358
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.393
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.396
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.397
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.394
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.395
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.400
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.401
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.398
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.399
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.402
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.379
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.378
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.377
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.376
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.383
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.382
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.380
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.388
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.387
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.386
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.384
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.392
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.391
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.390
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.389
Nav control imageConfiguration 2
line trunkNav control imageOR
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.400::lts
line trunkspacerNav control image* cpe:/a:cloudbees:jenkins:1.400.0.12::lts
Nav control imageConfiguration 3
spacerNav control imageOR
spacerspacerNav control image* cpe:/a:cloudbees:jenkins:1.400::enterprise
spacerspacerNav control image* cpe:/a:cloudbees:jenkins:1.400.0.12::enterprise
spacerspacerNav control image* cpe:/a:cloudbees:jenkins:1.424::enterprise
spacerspacerNav control image* cpe:/a:cloudbees:jenkins:1.424.5::enterprise
* Denotes Vulnerable Software

Technical Details

Vulnerability Type (View All)
  • Cross-Site Scripting (XSS) (CWE-79)