Stored Cross-Site Scripting in Jenkins Maven Repository Server Plugin
CVE-2023-35143
5.4MEDIUM
Key Information:
- Vendor
- Jenkins
- Vendor
- CVE Published:
- 14 June 2023
Summary
The Jenkins Maven Repository Server Plugin, specifically versions prior to 1.10, contains a stored cross-site scripting (XSS) vulnerability that occurs due to the failure to escape build artifact versions on the Build Artifacts As Maven Repository page. This security issue allows potential attackers to exploit the vulnerability by controlling Maven project versions specified in the 'pom.xml' file, leading to malicious scripts being executed in the context of unsuspecting users.
Affected Version(s)
Jenkins Maven Repository Server Plugin 0 <= 1.0
References
CVSS V3.1
Score:
5.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
Required
Scope:
Changed
Timeline
Vulnerability published
Vulnerability Reserved