CVE Database
/

CVE-2023-35141

Back to search

CVE-2023-35141

Published: Jun 14, 2023

Modified: Jan 2, 2025

PUBLISHED

Description

In Jenkins 2.399 and earlier, LTS 2.387.3 and earlier, POST requests are sent in order to load the list of context actions. If part of the URL includes insufficiently escaped user-provided values, a victim may be tricked into sending a POST request to an unexpected endpoint by opening a context menu.

VendorProductVersions

Jenkins Project

Jenkins

unaffected
2.400 - < *

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now