CVE-2023-41944: XSS
Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not escape the queue name parameter passed to a form validation URL, when rendering an error message, resulting in an HTML injection vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-41944?
CVE-2023-41944 is a vulnerability in the Jenkins AWS CodeCommit Trigger Plugin version 3.0.12 and earlier that allows HTML injection.
What is the severity of CVE-2023-41944?
The severity of CVE-2023-41944 is medium with a CVSS score of 6.1.
How does CVE-2023-41944 impact Jenkins AWS CodeCommit Trigger Plugin?
CVE-2023-41944 impacts Jenkins AWS CodeCommit Trigger Plugin version 3.0.12 and earlier by allowing HTML injection through a form validation URL.
How can I fix CVE-2023-41944?
To fix CVE-2023-41944, upgrade Jenkins AWS CodeCommit Trigger Plugin to version 3.0.13 or later.
Where can I find more information about CVE-2023-41944?
You can find more information about CVE-2023-41944 in the references mentioned in the vulnerability description: [Reference 1](http://www.openwall.com/lists/oss-security/2023/09/06/9) and [Reference 2](https://www.jenkins.io/security/advisory/2023-09-06/#SECURITY-3102).