CVE-2023-25762
Cross-site Scripting in Jenkins Pipeline: Build Step Plugin
5.4
MEDIUM
CVSS 3.1
EPSS 65.3%
Description
Jenkins Pipeline: Build Step Plugin 2.18 and earlier does not escape job names in a JavaScript expression used in the Pipeline Snippet Generator, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control job names.
How to fix CVE-2023-25762
To remediate CVE-2023-25762, upgrade the affected package to a fixed version below.
- —upgrade to 2.18.1 or later
Is CVE-2023-25762 being exploited?
Likely — EPSS is 65.3%, placing CVE-2023-25762 in the top tier of vulnerabilities by exploitation probability. Prioritise patching.
Affected packages (1)
- from 0, < 2.18.1
CVSS scores
| Source | Version | Severity | Vector |
|---|---|---|---|
| osv | CVSS 3.1 | MEDIUM5.4 | CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |