First published: Tue Dec 31 2013(Updated: )
Cross-site scripting (XSS) vulnerability in the default markup formatter in Jenkins 1.523 allows remote attackers to inject arbitrary web script or HTML via the Description field in the user configuration.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins | =1.523 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5573 is considered a medium severity vulnerability due to its potential for exploitation through XSS attacks.
To fix CVE-2013-5573, update Jenkins to a version later than 1.523 that has addressed this XSS vulnerability.
CVE-2013-5573 is a cross-site scripting (XSS) vulnerability affecting the default markup formatter in Jenkins.
Users of Jenkins version 1.523 are at risk of CVE-2013-5573 due to the exposure of the Description field in user configuration.
Attackers exploiting CVE-2013-5573 can inject arbitrary web scripts or HTML into the Jenkins application, potentially compromising users.