CVE-2023-46650: XSS
Jenkins GitHub Plugin 1.37.3 and earlier does not escape the GitHub project URL on the build page when showing changes, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Other sources
Jenkins GitHub Plugin 1.37.3 and earlier does not escape the GitHub project URL on the build page when showing changes.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
GitHub Plugin 1.37.3.1 escapes GitHub project URL on the build page when showing changes.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-46650?
CVE-2023-46650 is a vulnerability in Jenkins GitHub Plugin 1.37.3 and earlier that allows for stored cross-site scripting (XSS) attacks.
How severe is CVE-2023-46650?
CVE-2023-46650 has a severity rating of high, with a severity value of 8.
How can this vulnerability be exploited?
This vulnerability can be exploited by attackers with Item/Configure permission, allowing them to conduct stored cross-site scripting attacks.
What is the affected software?
The affected software is Jenkins GitHub Plugin 1.37.3 and earlier.
How do I fix CVE-2023-46650?
To fix CVE-2023-46650, update to version 1.37.3.1 of the Jenkins GitHub Plugin.