CVE-2023-41940: XSS
Published Sep 6, 2023
·Updated
Jenkins TAP Plugin 2.3 and earlier does not escape TAP file contents, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control TAP file contents.
Affected Software
2 affected components
maven/org.tap4j:tap<=2.3
Jenkins Tap Jenkins<=2.3
Event History
Sep 6, 2023
CVE Published
12:08 PM
Data Sourced
12:08 PM
Description
Advisory Published
via GitHub·03:30 PM
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
CVE-2023-41940
2
What is the title of this vulnerability?
Jenkins TAP Plugin 2.3 and earlier does not escape TAP file contents resulting in a stored cross-site scripting (XSS) vulnerability.
3
What is the severity of CVE-2023-41940?
The severity of CVE-2023-41940 is medium with a severity value of 5.4.
4
How can this vulnerability be exploited?
This vulnerability can be exploited by attackers who are able to control TAP file contents.
5
How do I fix CVE-2023-41940?
To fix CVE-2023-41940, update Jenkins TAP Plugin to version 2.4 or later.