cbcvebase.
CVE-2023-46650
published 2023-10-25

CVE-2023-46650: Jenkins GitHub Plugin 1.37.3 and earlier does not escape the GitHub project URL on the build page when showing changes, resulting in a stored cross-site…

medium5.4CVSS 3.1
AVNACLPRLUIRSCCLILAN
Jenkins GitHub Plugin 1.37.3 and earlier does not escape the GitHub project URL on the build page when showing changes, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

Affected

11 ranges
VendorProductVersion rangeFixed in
jenkinscloudbees_cd_plugin
jenkinsedgewall_trac_plugin
jenkinsgithub<= 1.37.3
jenkinsgithub_plugin
jenkinsgogs_plugin
jenkinsmsteams_webhook_trigger_plugin
jenkinsmultibranch_scan_webhook_trigger_plugin
jenkinsnon-constant_time_webhook_token_comparison_in_gogs_plugin
jenkinswarnings_plugin
jenkinszanata_plugin
jenkins_projectjenkins_github_plugin<= 1.37.3