DirectorySecurity Advisories
Sign In
Security Advisories

CGA-w255-fjh8-f3pm

Published

Last updated

https://images.chainguard.dev/security/CGA-w255-fjh8-f3pm
Package

jenkins

Latest Update
Fixed
Fixed Version

2.395-r0

Aliases
  • CVE-2023-27898
  • GHSA-j664-qhh4-hpf8

Severity

8.8

High

CVSS V3

Summary

Cross-site Scripting vulnerability in Jenkins

Description

Jenkins 2.270 through 2.393 (both inclusive), LTS 2.277.1 through 2.375.3 (both inclusive) does not escape the Jenkins version a plugin depends on when rendering the error message stating its incompatibility with the current version of Jenkins, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide plugins to the configured update sites and have this message shown by Jenkins instances.

References

Updates


Safe Source for Open Sourceâ„¢
Media KitContact Us
© 2024 Chainguard. All Rights Reserved.
Private PolicyTerms of Use

Product

Chainguard Images