PT-2023-2258 · Jenkins · Jenkins

Ilay Goldman

+1

·

Published

2023-03-08

·

Updated

2025-02-28

·

CVE-2023-27898

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins versions 2.270 through 2.393 Jenkins LTS versions 2.277.1 through 2.375.3
Description The issue is related to errors in handling HTTP headers, which can allow a remote attacker to perform cross-site scripting (XSS) attacks. The vulnerability is exploitable by attackers who can provide plugins to the configured update sites and have the error message shown by Jenkins instances. This results in a stored cross-site scripting (XSS) vulnerability.
Recommendations For Jenkins versions 2.270 through 2.393, update to a version outside of this range to resolve the issue. For Jenkins LTS versions 2.277.1 through 2.375.3, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to the plugin update sites to minimize the risk of exploitation.

Fix

XSS

Weakness Enumeration

Related Identifiers

BDU:2023-02017
BIT-JENKINS-2023-27898
CVE-2023-27898
GHSA-J664-QHH4-HPF8
RHSA-2023:1655
RHSA-2023:3663

Affected Products

Jenkins