CVE-2023-28678 Information
Apr 03, 2023
cve
Description
Jenkins Cppcheck Plugin 1.26 and earlier does not escape file names from Cppcheck report files before showing them on the Jenkins UI resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control report file contents.
Reference
https://www.jenkins.io/security/advisory/2023-03-21/#SECURITY-2809
Share on: