Vulnerabilities > Jenkins > Jacoco > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-04-02 CVE-2023-28669 Cross-site Scripting vulnerability in Jenkins Jacoco
Jenkins JaCoCo Plugin 3.3.2 and earlier does not escape class and method names shown on the UI, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control input files for the 'Record JaCoCo coverage report' post-build action.
network
low complexity
jenkins CWE-79
5.4