CVE-2023-4303
published 2023-08-21CVE-2023-4303: Jenkins Fortify Plugin 22.1.38 and earlier does not escape the error message for a form validation method, resulting in an HTML injection vulnerability.
medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
Jenkins Fortify Plugin 22.1.38 and earlier does not escape the error message for a form validation method, resulting in an HTML injection vulnerability.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| jenkins | blue_ocean_plugin | — | — |
| jenkins | config_file_provider_plugin | — | — |
| jenkins | delphix_plugin | — | — |
| jenkins | docker_swarm_plugin | — | — |
| jenkins | favorite_view_plugin | — | — |
| jenkins | flaky_test_handler_plugin | — | — |
| jenkins | folders_plugin | — | — |
| jenkins | fortify | < 22.2.39 | 22.2.39 |
| jenkins | fortify_plugin | — | — |
| jenkins | gogs_plugin | — | — |
| jenkins | improper_masking_of_credentials_in_nodejs_plugin | — | — |
| jenkins | nodejs_plugin | — | — |
| jenkins | shortcut_job_plugin | — | — |
| jenkins | tuleap_authentication_plugin | — | — |
| jenkins_project | jenkins_fortify_plugin | <= 22.1.38 | — |