FlawAtlas
Search the atlas
CVE-2023-25762 Moderate

CVE-2023-25762

Jenkins Pipeline: Build Step Plugin 2.18 and earlier does not escape job names in a JavaScript expression used in the Pipeline Snippet Generator, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control job names.

Exploit probability 81.4%
Published February 15, 2023
Required by Not available
Last source change July 9, 2026

02 / AFFECTED SOFTWARE

Affected packages

Unknown Unknown

19 explicit affected versions

Maven org.jenkins-ci.plugins:pipeline-build-step

23 explicit affected versions

04 / EVIDENCE

Source records

Open Source Vulnerabilities CVE-2023-25762

Jenkins Pipeline: Build Step Plugin 2.18 and earlier does not escape job names in a JavaScript expression used in the Pipeline Snippet Generator, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control job names.

View original source
Open Source Vulnerabilities GHSA-9j65-3f2q-8q2r

Jenkins Pipeline: Build Step Plugin 2.18 and earlier does not escape job names in a JavaScript expression used in the Pipeline Snippet Generator, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control job names.

View original source

05 / REFERENCES

Further evidence