FlawAtlas
Search the atlas
CVE-2023-25761 Moderate

CVE-2023-25761

Jenkins JUnit Plugin 1166.va_436e268e972 and earlier does not escape test case class names in JavaScript expressions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control test case class names in the JUnit resources processed by the plugin.

Exploit probability 0.7%
Published February 15, 2023
Required by Not available
Last source change July 9, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

83 explicit affected versions

Maven org.jenkins-ci.plugins:junit

86 explicit affected versions

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2023-25761

Jenkins JUnit Plugin 1166.va_436e268e972 and earlier does not escape test case class names in JavaScript expressions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control test case class names in the JUnit resources processed by the plugin.

View original source
Open Source Vulnerabilities GHSA-ph74-8rgx-64c5

Jenkins JUnit Plugin 1166.va_436e268e972 and earlier does not escape test case class names in JavaScript expressions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control test case class names in the JUnit resources processed by the plugin.

View original source

05 / REFERENCES

Further evidence