← Back to CVE List

CVE-2023-28669

Published: 2023-04-02T21:15Z
Last Modified: 2025-02-25T20:15Z
Source: MITRE CVE List
License: MITRE-CVE-TOS
Jenkins JaCoCo Plugin 3.3.2 and earlier does not escape class and method names shown on the UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control input files for the 'Record JaCoCo coverage report' post-build action. > MITRE Terms of Use apply – see LICENSE‑MITRE.txt