VulnerabilityModified
CVE-2023-43495
Jenkins 2.423 and earlier, LTS 2.414.1 and earlier does not escape the value of the 'caption' constructor parameter of 'ExpandableDetailsNote', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control this…
MEDIUM 5.4EPSS 0.88%
Does this matter?
Lower severity and a low EPSS score (0.88%). Track it; it rarely justifies an emergency change on its own.
Description
Jenkins 2.423 and earlier, LTS 2.414.1 and earlier does not escape the value of the 'caption' constructor parameter of 'ExpandableDetailsNote', resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control this parameter.
- CVSS 3.1
- 5.4 MEDIUMCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- EPSS
- 0.88% probability · 57th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- jenkins/jenkins
- Source
- jenkinsci-cert@googlegroups.com
References
- http://www.openwall.com/lists/oss-security/2023/09/20/5Mailing List, Third Party Advisory
- https://www.jenkins.io/security/advisory/2023-09-20/#SECURITY-3245Vendor Advisory
- http://www.openwall.com/lists/oss-security/2023/09/20/5Mailing List, Third Party Advisory
- https://www.jenkins.io/security/advisory/2023-09-20/#SECURITY-3245Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.