CVE-2023-35141
Last modified
CVE-2023-35141 is a high-severity vulnerability rated 8/10 on the CVSS scale. In Jenkins 2.399 and earlier, LTS 2.387.3 and earlier, POST requests are sent in order to load the list of context actions. If part of the URL includes insufficiently escaped user-provided values, a victim may be tricked into sending a POST request to an unexpected endpoint by opening a context menu.. EPSS estimates a 0.86% chance of exploitation in the next 30 days.
Description
In Jenkins 2.399 and earlier, LTS 2.387.3 and earlier, POST requests are sent in order to load the list of context actions. If part of the URL includes insufficiently escaped user-provided values, a victim may be tricked into sending a POST request to an unexpected endpoint by opening a context menu.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Jenkins | Jenkins | < 2.400 |
| Jenkins | Jenkins | < 2.401.1 |
References
- http://www.openwall.com/lists/oss-security/2023/06/14/5Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2023/06/14/5Mailing List, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-35141?
How severe is CVE-2023-35141?
How do I fix CVE-2023-35141?
Are you affected by CVE-2023-35141?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
