Sploitus

CVE-2023-27905

1 known exploit for CVE-2023-27905

Jenkins update-center2 3.13 and 3.14 renders the required Jenkins core version on plugin download index pages without sanitization, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a plugin for hosting.

Jenkins update-center2
= 3.13, 3.14
CVSS 3.1
9.6 CRITICAL
EPSS
1.5% (73th percentile)
Weakness
CWE-79
NVD status
Modified
Published
2023-03-08
CVE-2023-27905 at NVD
Authoritative description, scoring and affected products

1 known exploit for CVE-2023-27905

Proof-of-concept code and exploit modules indexed by Sploitus