Stored cross-site scripting vulnerability in Jenkins update-center2 by Jenkins
CVE-2023-27905

9.6CRITICAL

Key Information:

Vendor

Jenkins

Vendor
CVE Published:
10 March 2023

What is CVE-2023-27905?

The Jenkins update-center2 versions 3.13 and 3.14 are susceptible to a stored cross-site scripting (XSS) issue. This vulnerability arises because the required Jenkins core version is rendered on plugin download index pages without adequate sanitization. Attackers can exploit this weakness by uploading a malicious plugin for hosting, potentially compromising the integrity of the Jenkins environment and impacting users accessing these indices.

Affected Version(s)

Jenkins update-center2 3.13

Jenkins update-center2 3.14

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.