5.4
CVSSv3

CVE-2023-39151

Published: 26/07/2023 Updated: 03/08/2023
CVSS v3 Base Score: 5.4 | Impact Score: 2.7 | Exploitability Score: 2.3
VMScore: 0

Vulnerability Summary

Jenkins 2.415 and previous versions, LTS 2.401.2 and previous versions does not sanitize or properly encode URLs in build logs when transforming them into hyperlinks, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control build log contents.

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins jenkins

Vendor Advisories

DescriptionThe MITRE CVE dictionary describes this issue as: Jenkins 2415 and earlier, LTS 24012 and earlier does not sanitize or properly encode URLs in build logs when transforming them into hyperlinks, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control build log contents ...