CVE Database
/

CVE-2023-32977

Back to search

CVE-2023-32977

Published: May 16, 2023

Modified: Jan 23, 2025

PUBLISHED

Description

Jenkins Pipeline: Job Plugin does not escape the display name of the build that caused an earlier build to be aborted, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to set build display names immediately.

VendorProductVersions

Jenkins Project

Jenkins Pipeline: Job Plugin

unaffected
1295.v395eb_7400005 - < *
unaffected
1289.1291.vb_7c188e7e7df - < 1289.*
unaffected
1207.1209.v69351208a_5a_7 - < 1207.*

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now