CVE-2023-40346 is a stored cross-site scripting (XSS) vulnerability affecting Jenkins Shortcut Job Plugin versions 0.4 and earlier. Attackers with the ability to configure shortcut jobs can exploit this by injecting malicious scripts into the shortcut redirection URL, which is not properly escaped. Rated Medium (CVSS 5.4), this vulnerability requires user interaction and could lead to limited confidentiality and integrity impacts. There is currently no evidence of active exploitation, nor are public exploit tools like Metasploit or Nuclei available, though it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 0.4CPE matchmatch criteria | cpe:2.3:a:jenkins:shortcut_job:*:*:*:*:*:jenkins:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.