CVE-2023-25761 is a stored cross-site scripting (XSS) vulnerability affecting Jenkins JUnit Plugin versions 1166.va_436e268e972 and earlier. Attackers can exploit this by manipulating test case class names in JUnit resources, which are not properly escaped in JavaScript expressions. The vulnerability has a CVSS score of 5.4 (Medium), indicating a low-privileged attacker can trigger it with low complexity, leading to partial impact on confidentiality and integrity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1166.va_436e268e972CPE matchmatch criteria | cpe:2.3:a:jenkins:junit:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Cross-site Scripting in Jenkins JUnit Plugin
Feb 15, 2023jenkins-2-plugins/JUnit: Stored XSS vulnerability in JUnit Plugin
Feb 15, 2023Jenkins JUnit Plugin 1166.va_436e268e972 and earlier does not escape test case class names in JavaScript expressions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control test case class names in the JUnit resources processed by the plugin.
Feb 14, 2023