CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2023-27898

CVSS 9.6v3.1pub. 2023-03-10upd. 2025-02-28

Jenkins 2.270 through 2.393 (both inclusive), LTS 2.277.1 through 2.375.3 (both inclusive) does not escape the Jenkins version a plugin depends on when rendering the error message stating its incompatibility with the current version of Jenkins, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide plugins to the configured update sites and have this message shown by Jenkins instances.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
  • Jenkins

    APP
    Jenkins
    2.270 – 2.394 (excl.)2.277.1 – 2.375.4 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
XSSCI/CD
CWE
References

Related vulnerabilities

CVE-2024-23897CRITICAL9.8⚠ KEVPL ✓same product

Jenkins CLI – odczyt dowolnych plików przez path traversal bez uwierzytelnienia

CVE-2018-1000861CRITICAL9.8⚠ KEVPL ✓same product

RCE w Jenkins — nieuprawnione wywołanie metod przez Stapler framework

CVE-2017-1000353CRITICAL9.8⚠ KEVPL ✓same product

Jenkins CLI — nieuwierzytelnione RCE przez deserializację SignedObject

CVE-2021-21685CRITICAL9.1PL ✓same product

Jenkins: brak kontroli dostępu przy tworzeniu katalogów przez agenta

CVE-2021-21687CRITICAL9.1PL ✓same product

Jenkins: brak kontroli dostępu przy tworzeniu symbolic links przez agenty