CVE-2023-4303: HTML injection vulnerability in Fortify Plugin
Jenkins Fortify Plugin 22.1.38 and earlier does not escape the error message for a form validation method, resulting in an HTML injection vulnerability.
Other sources
Jenkins Fortify Plugin 22.1.38 and earlier does not escape the error message for a form validation method. This results in an HTML injection vulnerability.
Fortify Plugin 22.2.39 removes HTML tags from the error message.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-4303?
The severity of CVE-2023-4303 is medium with a CVSS score of 6.1.
What is the vulnerability in Jenkins Fortify Plugin 22.1.38 and earlier?
The vulnerability in Jenkins Fortify Plugin 22.1.38 and earlier is an HTML injection vulnerability.
How does Jenkins Fortify Plugin 22.2.39 fix the vulnerability?
Jenkins Fortify Plugin 22.2.39 fixes the vulnerability by removing HTML tags from the error message.
Where can I find more information about CVE-2023-4303?
You can find more information about CVE-2023-4303 on the Jenkins security advisory, NVD, and GitHub.
What is the CWE category of CVE-2023-4303?
The CWE category of CVE-2023-4303 is CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting').