Lucene search

K
cvelistJenkinsCVELIST:CVE-2023-25761
HistoryFeb 15, 2023 - 12:00 a.m.

CVE-2023-25761

2023-02-1500:00:00
jenkins
www.cve.org
7
cve-2023-25761
jenkins
junit plugin
xss
vulnerability
javascript
cross-site scripting

EPSS

0.001

Percentile

34.0%

Jenkins JUnit Plugin 1166.va_436e268e972 and earlier does not escape test case class names in JavaScript expressions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control test case class names in the JUnit resources processed by the plugin.

CNA Affected

[
  {
    "product": "Jenkins JUnit Plugin",
    "vendor": "Jenkins Project",
    "versions": [
      {
        "lessThanOrEqual": "1166.va_436e268e972",
        "status": "affected",
        "version": "unspecified",
        "versionType": "custom"
      },
      {
        "status": "unaffected",
        "version": "1119.1124.va_a_8ccde5658f"
      }
    ]
  }
]

EPSS

0.001

Percentile

34.0%