Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-27905


Jenkins update-center2 3.13 and 3.14 renders the required Jenkins core version on plugin download index pages without sanitization, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a plugin for hosting.


Published

2023-03-10T21:15:15.790

Last Modified

2025-02-28T19:15:36.040

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.6 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-79
  • Type: Secondary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application jenkins update-center2 3.13 Yes
Application jenkins update-center2 3.14 Yes

References