CVE-2023-32977
16.05.2023, 16:15
Jenkins Pipeline: Job Plugin does not escape the display name of the build that caused an earlier build to be aborted, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to set build display names immediately.
Vendor | Product | Version |
---|---|---|
jenkins | pipeline\ | 𝑥 ≤ 1292.v27d8cc3e2602 |
𝑥
= Vulnerable software versions