CVE-2023-27905

CVSS v3.1 9.6 (Critical)
96% Progress
EPSS 0.19 % (56th)
0.19% Progress
Affected Products 1
Advisories 2

Jenkins update-center2 3.13 and 3.14 renders the required Jenkins core version on plugin download index pages without sanitization, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a plugin for hosting.

Weaknesses
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE Status
PUBLISHED
CNA
Jenkins Project
Published Date
2023-03-10 21:15:15
(18 months ago)
Updated Date
2023-05-24 17:43:49
(16 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Jenkins Update-center2 3.13 for Jenkins cpe:2.3:a:jenkins:update-center2:3.13:*:*:*:*:jenkins
  Jenkins Update-center2 3.14 for Jenkins cpe:2.3:a:jenkins:update-center2:3.14:*:*:*:*:jenkins
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...