Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-27898


Jenkins 2.270 through 2.393 (both inclusive), LTS 2.277.1 through 2.375.3 (both inclusive) does not escape the Jenkins version a plugin depends on when rendering the error message stating its incompatibility with the current version of Jenkins, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide plugins to the configured update sites and have this message shown by Jenkins instances.


Published

2023-03-10T21:15:15.403

Last Modified

2025-02-28T19:15:34.900

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.6 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-79
  • Type: Secondary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application jenkins jenkins < 2.394 Yes
Application jenkins jenkins < 2.375.4 Yes

References