CVE Database
/

CVE-2023-35146

Back to search

CVE-2023-35146

Published: Jun 14, 2023

Modified: Dec 31, 2024

PUBLISHED

Description

Jenkins Template Workflows Plugin 41.v32d86a_313b_4a and earlier does not escape names of jobs used as buildings blocks for Template Workflow Job, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create jobs.

VendorProductVersions

Jenkins Project

Jenkins Template Workflows Plugin

affected
0 - <= 41.v32d86a_313b_4a

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now