CVE-2012-0325
Summary
| CVE | CVE-2012-0325 |
|---|---|
| State | PUBLISHED |
| Assigner | jpcert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2012-03-09 11:55:01 UTC |
| Updated | 2026-04-29 01:13:23 UTC |
| Description | Cross-site scripting (XSS) vulnerability in Jenkins before 1.454, Jenkins LTS before 1.424.5, and Jenkins Enterprise 1.400.x before 1.400.0.13 and 1.424.x before 1.424.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2012-0324. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
MediumAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
NoneAV:N/AC:M/Au:N/C:N/I:P/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Cloudbees | Jenkins | 1.400 | All | enterprise | All |
| Application | Cloudbees | Jenkins | 1.400 | All | lts | All |
| Application | Cloudbees | Jenkins | 1.400.0.12 | All | enterprise | All |
| Application | Cloudbees | Jenkins | 1.400.0.12 | All | lts | All |
| Application | Cloudbees | Jenkins | 1.424 | All | enterprise | All |
| Application | Cloudbees | Jenkins | 1.424.5 | All | enterprise | All |
| Application | Cloudbees | Jenkins | All | All | All | All |
| Application | Jenkins | Jenkins | 1.301 | All | All | All |
| Application | Jenkins | Jenkins | 1.302 | All | All | All |
| Application | Jenkins | Jenkins | 1.303 | All | All | All |
| Application | Jenkins | Jenkins | 1.304 | All | All | All |
| Application | Jenkins | Jenkins | 1.305 | All | All | All |
| Application | Jenkins | Jenkins | 1.306 | All | All | All |
| Application | Jenkins | Jenkins | 1.307 | All | All | All |
| Application | Jenkins | Jenkins | 1.308 | All | All | All |
| Application | Jenkins | Jenkins | 1.309 | All | All | All |
| Application | Jenkins | Jenkins | 1.310 | All | All | All |
| Application | Jenkins | Jenkins | 1.311 | All | All | All |
| Application | Jenkins | Jenkins | 1.312 | All | All | All |
| Application | Jenkins | Jenkins | 1.313 | All | All | All |
| Application | Jenkins | Jenkins | 1.314 | All | All | All |
| Application | Jenkins | Jenkins | 1.315 | All | All | All |
| Application | Jenkins | Jenkins | 1.316 | All | All | All |
| Application | Jenkins | Jenkins | 1.317 | All | All | All |
| Application | Jenkins | Jenkins | 1.318 | All | All | All |
| Application | Jenkins | Jenkins | 1.319 | All | All | All |
| Application | Jenkins | Jenkins | 1.320 | All | All | All |
| Application | Jenkins | Jenkins | 1.321 | All | All | All |
| Application | Jenkins | Jenkins | 1.322 | All | All | All |
| Application | Jenkins | Jenkins | 1.323 | All | All | All |
| Application | Jenkins | Jenkins | 1.324 | All | All | All |
| Application | Jenkins | Jenkins | 1.325 | All | All | All |
| Application | Jenkins | Jenkins | 1.326 | All | All | All |
| Application | Jenkins | Jenkins | 1.327 | All | All | All |
| Application | Jenkins | Jenkins | 1.328 | All | All | All |
| Application | Jenkins | Jenkins | 1.329 | All | All | All |
| Application | Jenkins | Jenkins | 1.330 | All | All | All |
| Application | Jenkins | Jenkins | 1.331 | All | All | All |
| Application | Jenkins | Jenkins | 1.332 | All | All | All |
| Application | Jenkins | Jenkins | 1.333 | All | All | All |
| Application | Jenkins | Jenkins | 1.334 | All | All | All |
| Application | Jenkins | Jenkins | 1.335 | All | All | All |
| Application | Jenkins | Jenkins | 1.336 | All | All | All |
| Application | Jenkins | Jenkins | 1.337 | All | All | All |
| Application | Jenkins | Jenkins | 1.338 | All | All | All |
| Application | Jenkins | Jenkins | 1.339 | All | All | All |
| Application | Jenkins | Jenkins | 1.340 | All | All | All |
| Application | Jenkins | Jenkins | 1.341 | All | All | All |
| Application | Jenkins | Jenkins | 1.342 | All | All | All |
| Application | Jenkins | Jenkins | 1.343 | All | All | All |
| Application | Jenkins | Jenkins | 1.344 | All | All | All |
| Application | Jenkins | Jenkins | 1.345 | All | All | All |
| Application | Jenkins | Jenkins | 1.346 | All | All | All |
| Application | Jenkins | Jenkins | 1.347 | All | All | All |
| Application | Jenkins | Jenkins | 1.348 | All | All | All |
| Application | Jenkins | Jenkins | 1.349 | All | All | All |
| Application | Jenkins | Jenkins | 1.350 | All | All | All |
| Application | Jenkins | Jenkins | 1.351 | All | All | All |
| Application | Jenkins | Jenkins | 1.352 | All | All | All |
| Application | Jenkins | Jenkins | 1.353 | All | All | All |
| Application | Jenkins | Jenkins | 1.354 | All | All | All |
| Application | Jenkins | Jenkins | 1.355 | All | All | All |
| Application | Jenkins | Jenkins | 1.356 | All | All | All |
| Application | Jenkins | Jenkins | 1.357 | All | All | All |
| Application | Jenkins | Jenkins | 1.358 | All | All | All |
| Application | Jenkins | Jenkins | 1.359 | All | All | All |
| Application | Jenkins | Jenkins | 1.360 | All | All | All |
| Application | Jenkins | Jenkins | 1.361 | All | All | All |
| Application | Jenkins | Jenkins | 1.362 | All | All | All |
| Application | Jenkins | Jenkins | 1.363 | All | All | All |
| Application | Jenkins | Jenkins | 1.364 | All | All | All |
| Application | Jenkins | Jenkins | 1.365 | All | All | All |
| Application | Jenkins | Jenkins | 1.366 | All | All | All |
| Application | Jenkins | Jenkins | 1.367 | All | All | All |
| Application | Jenkins | Jenkins | 1.368 | All | All | All |
| Application | Jenkins | Jenkins | 1.369 | All | All | All |
| Application | Jenkins | Jenkins | 1.370 | All | All | All |
| Application | Jenkins | Jenkins | 1.371 | All | All | All |
| Application | Jenkins | Jenkins | 1.372 | All | All | All |
| Application | Jenkins | Jenkins | 1.373 | All | All | All |
| Application | Jenkins | Jenkins | 1.374 | All | All | All |
| Application | Jenkins | Jenkins | 1.375 | All | All | All |
| Application | Jenkins | Jenkins | 1.376 | All | All | All |
| Application | Jenkins | Jenkins | 1.377 | All | All | All |
| Application | Jenkins | Jenkins | 1.378 | All | All | All |
| Application | Jenkins | Jenkins | 1.379 | All | All | All |
| Application | Jenkins | Jenkins | 1.380 | All | All | All |
| Application | Jenkins | Jenkins | 1.382 | All | All | All |
| Application | Jenkins | Jenkins | 1.383 | All | All | All |
| Application | Jenkins | Jenkins | 1.384 | All | All | All |
| Application | Jenkins | Jenkins | 1.386 | All | All | All |
| Application | Jenkins | Jenkins | 1.387 | All | All | All |
| Application | Jenkins | Jenkins | 1.388 | All | All | All |
| Application | Jenkins | Jenkins | 1.389 | All | All | All |
| Application | Jenkins | Jenkins | 1.390 | All | All | All |
| Application | Jenkins | Jenkins | 1.391 | All | All | All |
| Application | Jenkins | Jenkins | 1.392 | All | All | All |
| Application | Jenkins | Jenkins | 1.393 | All | All | All |
| Application | Jenkins | Jenkins | 1.394 | All | All | All |
| Application | Jenkins | Jenkins | 1.395 | All | All | All |
| Application | Jenkins | Jenkins | 1.396 | All | All | All |
| Application | Jenkins | Jenkins | 1.397 | All | All | All |
| Application | Jenkins | Jenkins | 1.398 | All | All | All |
| Application | Jenkins | Jenkins | 1.399 | All | All | All |
| Application | Jenkins | Jenkins | 1.400 | All | All | All |
| Application | Jenkins | Jenkins | 1.401 | All | All | All |
| Application | Jenkins | Jenkins | 1.402 | All | All | All |
| Application | Jenkins | Jenkins | 1.403 | All | All | All |
| Application | Jenkins | Jenkins | 1.404 | All | All | All |
| Application | Jenkins | Jenkins | 1.405 | All | All | All |
| Application | Jenkins | Jenkins | 1.406 | All | All | All |
| Application | Jenkins | Jenkins | 1.407 | All | All | All |
| Application | Jenkins | Jenkins | 1.408 | All | All | All |
| Application | Jenkins | Jenkins | 1.409 | All | All | All |
| Application | Jenkins | Jenkins | 1.409.1 | All | All | All |
| Application | Jenkins | Jenkins | 1.409.2 | All | All | All |
| Application | Jenkins | Jenkins | 1.410 | All | All | All |
| Application | Jenkins | Jenkins | 1.411 | All | All | All |
| Application | Jenkins | Jenkins | 1.412 | All | All | All |
| Application | Jenkins | Jenkins | 1.413 | All | All | All |
| Application | Jenkins | Jenkins | 1.414 | All | All | All |
| Application | Jenkins | Jenkins | 1.415 | All | All | All |
| Application | Jenkins | Jenkins | 1.416 | All | All | All |
| Application | Jenkins | Jenkins | 1.417 | All | All | All |
| Application | Jenkins | Jenkins | 1.418 | All | All | All |
| Application | Jenkins | Jenkins | 1.419 | All | All | All |
| Application | Jenkins | Jenkins | 1.420 | All | All | All |
| Application | Jenkins | Jenkins | 1.421 | All | All | All |
| Application | Jenkins | Jenkins | 1.422 | All | All | All |
| Application | Jenkins | Jenkins | 1.423 | All | All | All |
| Application | Jenkins | Jenkins | 1.424 | All | All | All |
| Application | Jenkins | Jenkins | 1.425 | All | All | All |
| Application | Jenkins | Jenkins | 1.426 | All | All | All |
| Application | Jenkins | Jenkins | 1.427 | All | All | All |
| Application | Jenkins | Jenkins | 1.428 | All | All | All |
| Application | Jenkins | Jenkins | 1.429 | All | All | All |
| Application | Jenkins | Jenkins | 1.430 | All | All | All |
| Application | Jenkins | Jenkins | 1.431 | All | All | All |
| Application | Jenkins | Jenkins | 1.432 | All | All | All |
| Application | Jenkins | Jenkins | 1.433 | All | All | All |
| Application | Jenkins | Jenkins | 1.434 | All | All | All |
| Application | Jenkins | Jenkins | 1.435 | All | All | All |
| Application | Jenkins | Jenkins | 1.436 | All | All | All |
| Application | Jenkins | Jenkins | 1.437 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| JVN#79950061: Jenkins vulnerable to cross-site scripting | af854a3a-2127-422b-91ae-364da2661108 | jvn.jp | |
| Jenkins Multiple Cross Site Scripting and Directory Traversal Vulnerabilities | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CloudBees: The Java PaaS Company | af854a3a-2127-422b-91ae-364da2661108 | www.cloudbees.com | Vendor Advisory |
| jvndb.jvn.jp/jvndb/JVNDB-2012-000023 | af854a3a-2127-422b-91ae-364da2661108 | jvndb.jvn.jp | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.