Back to search
CVE-2023-35146
Published: Jun 14, 2023
Modified: Dec 31, 2024
PUBLISHED
Description
Jenkins Template Workflows Plugin 41.v32d86a_313b_4a and earlier does not escape names of jobs used as buildings blocks for Template Workflow Job, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create jobs.
| Vendor | Product | Versions |
|---|---|---|
Jenkins Project | Jenkins Template Workflows Plugin | affected 0 - <= 41.v32d86a_313b_4a |
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now