First published: Wed Aug 16 2023(Updated: )
Jenkins Shortcut Job Plugin 0.4 and earlier does not escape the shortcut redirection URL, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure shortcut jobs.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Shortcut Job | <=0.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for the Jenkins Shortcut Job Plugin vulnerability is CVE-2023-40346.
The severity of CVE-2023-40346 is high with a severity value of 8.
The Jenkins Shortcut Job Plugin vulnerability occurs due to the plugin's failure to escape the shortcut redirection URL.
The Jenkins Shortcut Job Plugin vulnerability can be exploited by attackers who are able to configure shortcut jobs.
To fix the Jenkins Shortcut Job Plugin vulnerability, update to version 0.5 of the Shortcut Job Plugin which escapes the shortcut redirection URL.