CVE-2023-25763
published 2023-02-15CVE-2023-25763: Jenkins Email Extension Plugin 2.93 and earlier does not escape various fields included in bundled email templates, resulting in a stored cross-site scripting…
medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
Jenkins Email Extension Plugin 2.93 and earlier does not escape various fields included in bundled email templates, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control affected fields.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | azure_credentials_plugin | — | — |
| jenkins | build_step_plugin | — | — |
| jenkins | config_file_provider_plugin | — | — |
| jenkins | email_extension | < 2.93.1 | 2.93.1 |
| jenkins | email_extension_plugin | — | — |
| jenkins | junit_plugin | — | — |
| jenkins | junit_resources_processed_by_the_plugin | — | — |
| jenkins | synopsys_coverity_plugin | — | — |
| jenkins_project | jenkins_email_extension_plugin | unspecified – 2.93 | — |