First published: Wed Sep 20 2023(Updated: )
Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier does not escape Failure Cause names in build logs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create or update Failure Causes.
Credit: jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com jenkinsci-cert@googlegroups.com
Affected Software | Affected Version | How to fix |
---|---|---|
Jenkins Build Failure Analyzer | <2.4.2 | |
maven/com.sonyericsson.jenkins.plugins.bfa:build-failure-analyzer | <2.4.2 | 2.4.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-43499.
The severity of CVE-2023-43499 is high with a severity value of 8.
The affected software is Jenkins Build Failure Analyzer Plugin version 2.4.1 and earlier.
This vulnerability can be exploited by attackers able to create or update Failure Causes in build logs.
To fix CVE-2023-43499, update to version 2.4.2 of the Jenkins Build Failure Analyzer Plugin.