Description
Jenkins 2.270 through 2.393 (both inclusive), LTS 2.277.1 through 2.375.3 (both inclusive) does not escape the Jenkins version a plugin depends on when rendering the error message stating its incompatibility with the current version of Jenkins, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide plugins to the configured update sites and have this message shown by Jenkins instances.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1045 | Jenkins 2.270 through 2.393 (both inclusive), LTS 2.277.1 through 2.375.3 (both inclusive) does not escape the Jenkins version a plugin depends on when rendering the error message stating its incompatibility with the current version of Jenkins, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide plugins to the configured update sites and have this message shown by Jenkins instances. |
Github GHSA |
GHSA-j664-qhh4-hpf8 | Cross-site Scripting vulnerability in Jenkins |
References
History
Tue, 04 Mar 2025 03:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-02-28T18:34:50.742Z
Reserved: 2023-03-07T09:35:48.506Z
Link: CVE-2023-27898
Updated: 2024-08-02T12:23:30.482Z
Status : Modified
Published: 2023-03-10T21:15:15.403
Modified: 2025-02-28T19:15:34.900
Link: CVE-2023-27898
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA