Stored Cross-Site Scripting Vulnerability in Jenkins JUnit Plugin
CVE-2023-25761
5.4MEDIUM
Key Information:
- Vendor
Jenkins
- Status
- Vendor
- CVE Published:
- 15 February 2023
What is CVE-2023-25761?
The Jenkins JUnit Plugin prior to version 1166.va_436e268e972 is susceptible to a stored cross-site scripting vulnerability due to improper escaping of test case class names in JavaScript expressions. This vulnerability allows attackers, who can manipulate the test case class names within the JUnit resources processed by the plugin, to execute arbitrary JavaScript in the context of a user's session. This could lead to unauthorized actions, data theft, or further exploitation of the affected system.
Affected Version(s)
Jenkins JUnit Plugin <= 1166.va_436e268e972
Jenkins JUnit Plugin 1119.1124.va_a_8ccde5658f