CVE-2023-43499

Severity
5.4MEDIUM
EPSS
4.3%
top 11.09%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 20

Description

Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier does not escape Failure Cause names in build logs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create or update Failure Causes.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:NExploitability: 2.3 | Impact: 2.7

🔴Vulnerability Details

3
GHSA
Jenkins Build Failure Analyzer Plugin Cross-site Scripting vulnerability2023-09-20
CVEList
CVE-2023-43499: Jenkins Build Failure Analyzer Plugin 22023-09-20
OSV
Jenkins Build Failure Analyzer Plugin Cross-site Scripting vulnerability2023-09-20

📋Vendor Advisories

1
Jenkins
Jenkins Security Advisory 2023-09-202023-09-20