PT-2023-25161 · Jenkins · Jenkins

Kevin Guerroudj

·

Published

2023-06-14

·

Updated

2025-01-02

·

CVE-2023-35141

CVSS v3.1

8.0

High

VectorAV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Jenkins versions 2.399 and earlier, LTS versions 2.387.3 and earlier
Description The issue arises when POST requests are sent to load the list of context actions. If part of the URL includes insufficiently escaped user-provided values, a victim may be tricked into sending a POST request to an unexpected endpoint, such as the Script Console, by opening a context menu. This can be exploited by attackers with Item/Configure permissions, particularly through insufficiently escaped context menu URLs for label expressions.
Recommendations For Jenkins versions 2.399 and earlier, update to version 2.400 or later to resolve the issue. For LTS versions 2.387.3 and earlier, update to version 2.401.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the context menu or limiting the permissions of users who can configure items to minimize the risk of exploitation.

Exploit

Fix

CSRF

Weakness Enumeration

Related Identifiers

BIT-JENKINS-2023-35141
CVE-2023-35141
GHSA-98FP-R22G-WPJ7

Affected Products

Jenkins