BIT-jenkins-2023-27898
Dashboard / Vulnerabilities / BIT-jenkins-2023-27898
BIT-jenkins-2023-27898
Published: 6 Mar 2024Last Modified: 8 Sept 2026
Aliases:
Summary:
Details: Jenkins LTS 2.277.1 through 2.375.3 (both inclusive) does not escape the Jenkins version a plugin depends on when rendering the error message stating its incompatibility with the current version of Jenkins, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide plugins to the configured update sites and have this message shown by Jenkins instances.
References: https://www.jenkins.io/security/advisory/2023-03-08/#SECURITY-3037, https://nvd.nist.gov/vuln/detail/CVE-2023-27898
Affected packages
Package
Name: jenkins
Purl: pkg:bitnami/jenkins
Affected ranges
Type: SEMVER
Events:
Introduced- 2.270.0
Fixed -2.394.0
Affected versions
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
