CVE Database
/

CVE-2023-28678

Back to search

CVE-2023-28678

Published: Mar 23, 2023

Modified: Feb 25, 2025

PUBLISHED

Description

Jenkins Cppcheck Plugin 1.26 and earlier does not escape file names from Cppcheck report files before showing them on the Jenkins UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control report file contents.

VendorProductVersions

Jenkins Project

Jenkins Cppcheck Plugin

affected
0 - <= 1.26

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now