PT-2023-21890 · Jenkins · Jenkins Jacoco Plugin+1

Crilwa

+1

·

Publicado

2023-03-23

·

Atualizado

2025-02-25

·

CVE-2023-28669

CVSS v3.1

8.0

Alta

VetorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins JaCoCo Plugin versions 3.3.2 and earlier
Description The issue is a stored cross-site scripting (XSS) vulnerability. It occurs because class and method names shown on the UI are not escaped, allowing attackers who can control input files for the 'Record JaCoCo coverage report' post-build action to exploit this vulnerability.
Recommendations For versions 3.3.2 and earlier, update to version 3.3.2.1 or later, which escapes class and method names shown on the UI, addressing the stored cross-site scripting (XSS) vulnerability.

Correção

XSS

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-28669
GHSA-XJ29-GFWW-J67G

Produtos afetados

Jenkins
Jenkins Jacoco Plugin