CVE-2023-46659: XSS
Jenkins Edgewall Trac Plugin 1.13 and earlier does not escape the Trac website URL on the build page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Other sources
Jenkins Edgewall Trac Plugin 1.13 and earlier does not escape the Trac website URL on the build page.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
As of publication of this advisory, there is no fix.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Jenkins Edgewall Trac Plugin vulnerability?
The vulnerability ID is CVE-2023-46659.
What is the severity of CVE-2023-46659?
The severity of CVE-2023-46659 is medium.
What is the affected software for CVE-2023-46659?
The affected software is Jenkins Edgewall Trac Plugin version 1.13 and earlier.
What is the CWE ID for CVE-2023-46659?
The CWE ID for CVE-2023-46659 is CWE-79.
How can I fix the Jenkins Edgewall Trac Plugin vulnerability (CVE-2023-46659)?
To fix the vulnerability, update to Jenkins Edgewall Trac Plugin version 1.14 or later.