Lucene search

K
cvelistJenkinsCVELIST:CVE-2023-27905
HistoryMar 08, 2023 - 5:14 p.m.

CVE-2023-27905

2023-03-0817:14:53
jenkins
www.cve.org
1
cve-2023-27905
jenkins
update-center2
cross-site scripting
plugin download

8.5 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

54.2%

Jenkins update-center2 3.13 and 3.14 renders the required Jenkins core version on plugin download index pages without sanitization, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a plugin for hosting.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Jenkins update-center2",
    "vendor": "Jenkins Project",
    "versions": [
      {
        "status": "affected",
        "version": "3.13"
      },
      {
        "status": "affected",
        "version": "3.14"
      }
    ]
  }
]

8.5 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

54.2%

Related for CVELIST:CVE-2023-27905