Stored Cross-Site Scripting in Jenkins Docker Swarm Plugin by CloudBees
CVE-2023-40350
What is CVE-2023-40350?
The Jenkins Docker Swarm Plugin version 1.11 and earlier contains a stored cross-site scripting vulnerability due to improper escaping of data returned from Docker. This oversight allows malicious actors with the ability to control Docker response values to execute arbitrary JavaScript code in the context of the user’s browser, potentially compromising user accounts and exposing sensitive information through the Docker Swarm Dashboard view. To mitigate the risk, it is crucial for users to upgrade to the latest version of the plugin as recommended in the Jenkins Security Advisory.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Jenkins Docker Swarm Plugin 0 <= 1.11
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved