4.3
CVSSv3

CVE-2023-41930

Published: 06/09/2023 Updated: 11/09/2023
CVSS v3 Base Score: 4.3 | Impact Score: 1.4 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Jenkins Job Configuration History Plugin 1227.v7a_79fc4dc01f and previous versions does not restrict the 'name' query parameter when rendering a history entry, allowing malicious users to have Jenkins render a manipulated configuration history that was not created by the plugin.

Vulnerable Product Search on Vulmon Subscribe to Product

jenkins job configuration history