PT-2023-6025 · Jenkins · Jenkins Fortify Plugin+1
Kevin Guerroudj
·
Published
2023-08-21
·
Updated
2023-08-24
·
CVE-2023-4303
CVSS v2.0
6.4
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:N |
Name of the Vulnerable Software and Affected Versions
Jenkins Fortify Plugin versions 22.1.38 and earlier
Description
The issue is related to the failure to protect the web page structure, allowing a remote attacker to perform an HTML injection. This occurs because the error message for a form validation method is not properly escaped, resulting in an HTML injection vulnerability.
Recommendations
For Jenkins Fortify Plugin versions 22.1.38 and earlier, update to version 22.2.39 or later, which removes HTML tags from the error message, thus resolving the issue.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jenkins
Jenkins Fortify Plugin