Jenkins 2.415 and earlier, LTS 2.401.2 and earlier does not sanitize or properly encode URLs in build logs when transforming them into hyperlinks, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control build log contents.
CVSS
No CVSS.
References
Configurations
No configuration.
Information
Published : 2023-07-26 14:15
Updated : 2023-07-26 19:28
NVD link : CVE-2023-39151
Mitre link : CVE-2023-39151
JSON object : View
Products Affected
No product.
CWE
No CWE.
