PT-2023-21891 · Jenkins · Jenkins Pipeline Aggregator View Plugin+1

Kevin Guerroudj

·

Published

2023-03-23

·

Updated

2023-04-07

·

CVE-2023-28670

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Jenkins Pipeline Aggregator View Plugin versions 1.13 and earlier
Description The issue is related to a stored cross-site scripting (XSS) vulnerability. It occurs because a variable representing the current view's URL is not properly escaped in inline JavaScript. This vulnerability can be exploited by authenticated attackers who have Overall/Read permission.
Recommendations For Jenkins Pipeline Aggregator View Plugin versions 1.13 and earlier, update to version 1.14 or later to resolve the issue.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2023-28670
GHSA-V27Q-87JF-J9CR

Affected Products

Jenkins
Jenkins Pipeline Aggregator View Plugin