CVE-2023-41944 Information

Description

Jenkins AWS CodeCommit Trigger Plugin 3.0.12 and earlier does not escape the queue name parameter passed to a form validation URL when rendering an error message resulting in an HTML injection vulnerability.

Reference

https://www.jenkins.io/security/advisory/2023-09-06/#SECURITY-3102 http://www.openwall.com/lists/oss-security/2023/09/06/9

Share on: