Stored Cross-Site Scripting in Jenkins Maven Repository Server Plugin
CVE-2023-35143
5.4MEDIUM
Key Information:
- Vendor
Jenkins
- Vendor
- CVE Published:
- 14 June 2023
What is CVE-2023-35143?
The Jenkins Maven Repository Server Plugin, specifically versions prior to 1.10, contains a stored cross-site scripting (XSS) vulnerability that occurs due to the failure to escape build artifact versions on the Build Artifacts As Maven Repository page. This security issue allows potential attackers to exploit the vulnerability by controlling Maven project versions specified in the 'pom.xml' file, leading to malicious scripts being executed in the context of unsuspecting users.
Affected Version(s)
Jenkins Maven Repository Server Plugin 0 <= 1.0