Lucene search

K
prionPRIOn knowledge basePRION:CVE-2023-27905
HistoryMar 10, 2023 - 9:15 p.m.

Cross site scripting

2023-03-1021:15:00
PRIOn knowledge base
www.prio-n.com
14
jenkins
update-center2
xss
vulnerability
exploit
plugin hosting

8.2 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

54.2%

Jenkins update-center2 3.13 and 3.14 renders the required Jenkins core version on plugin download index pages without sanitization, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a plugin for hosting.

CPENameOperatorVersion
update-center2eq3.14
update-center2eq3.13

8.2 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

54.2%

Related for PRION:CVE-2023-27905