Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2023-1394 | Jenkins Pipeline Aggregator View Plugin 1.13 and earlier does not escape a variable representing the current view's URL in inline JavaScript, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by authenticated attackers with Overall/Read permission. |
Github GHSA |
GHSA-v27q-87jf-j9cr | Jenkins Pipeline Aggregator View Plugin vulnerable to Cross-site Scripting |
Tue, 25 Feb 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-02-25T21:01:15.828Z
Reserved: 2023-03-20T19:59:08.755Z
Link: CVE-2023-28670
Updated: 2024-08-02T13:43:23.668Z
Status : Modified
Published: 2023-04-02T21:15:08.847
Modified: 2025-02-25T21:15:14.027
Link: CVE-2023-28670
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA