Home

Description

Jenkins 2.415 and earlier, LTS 2.401.2 and earlier does not sanitize or properly encode URLs in build logs when transforming them into hyperlinks, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control build log contents.

PUBLISHED Reserved 2023-07-25 | Published 2023-07-26 | Updated 2024-10-21 | Assigner jenkins

Product status

Default status
affected

2.416 (maven) before *
unaffected

2.401.3 (maven) before 2.401.*
unaffected

2.414.1 (maven) before 2.414.*
unaffected

References

www.jenkins.io/security/advisory/2023-07-26/ (Jenkins Security Advisory 2023-07-26) vendor-advisory

www.openwall.com/lists/oss-security/2023/07/26/2

cve.org (CVE-2023-39151)

nvd.nist.gov (CVE-2023-39151)

Download JSON