PT-2023-2258 · Jenkins · Jenkins
Ilay Goldman
+1
·
Published
2023-03-08
·
Updated
2025-02-28
·
CVE-2023-27898
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Jenkins versions 2.270 through 2.393
Jenkins LTS versions 2.277.1 through 2.375.3
Description
The issue is related to errors in handling HTTP headers, which can allow a remote attacker to perform cross-site scripting (XSS) attacks. The vulnerability is exploitable by attackers who can provide plugins to the configured update sites and have the error message shown by Jenkins instances. This results in a stored cross-site scripting (XSS) vulnerability.
Recommendations
For Jenkins versions 2.270 through 2.393, update to a version outside of this range to resolve the issue.
For Jenkins LTS versions 2.277.1 through 2.375.3, update to a version outside of this range to resolve the issue.
As a temporary workaround, consider restricting access to the plugin update sites to minimize the risk of exploitation.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins