PT-2023-21890 · Jenkins · Jenkins Jacoco Plugin+1
Crilwa
+1
·
Published
2023-03-23
·
Updated
2025-02-25
·
CVE-2023-28669
CVSS v3.1
8.0
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Jenkins JaCoCo Plugin versions 3.3.2 and earlier
Description
The issue is a stored cross-site scripting (XSS) vulnerability. It occurs because class and method names shown on the UI are not escaped, allowing attackers who can control input files for the 'Record JaCoCo coverage report' post-build action to exploit this vulnerability.
Recommendations
For versions 3.3.2 and earlier, update to version 3.3.2.1 or later, which escapes class and method names shown on the UI, addressing the stored cross-site scripting (XSS) vulnerability.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Jacoco Plugin