CVE-2023-25761
15.02.2023, 14:15
Jenkins JUnit Plugin 1166.va_436e268e972 and earlier does not escape test case class names in JavaScript expressions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control test case class names in the JUnit resources processed by the plugin.
Vendor | Product | Version |
---|---|---|
jenkins | junit | 𝑥 ≤ 1166.va_436e268e972 |
𝑥
= Vulnerable software versions