Back to Database
Status published
Medium
CVE-2023-4303
HTML injection vulnerability in Fortify Plugin
Vulnerability Description
Jenkins Fortify Plugin 22.1.38 and earlier does not escape the error message for a form validation method, resulting in an HTML injection vulnerability.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-4303
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Kevin Guerroudj, CloudBees, Inc.
More from Jenkins Project
View All →CVE-2025-67643
Jenkins Redpen - Pipeline Reporter for Jira Plugin 1.054.v7b_9517b_6b_202 and...
Unknown
0
CVE-2025-67642
Jenkins HashiCorp Vault Plugin 371.v884a_4dd60fb_6 and earlier does not set...
Unknown
0
CVE-2025-67641
Jenkins Coverage Plugin 2.3054.ve1ff7b_a_a_123b_ and earlier does not validate the...
Unknown
0
CVE-2025-67640
Jenkins Git client Plugin 6.4.0 and earlier does not not...
Unknown
0
CVE-2025-67639
A cross-site request forgery (CSRF) vulnerability in Jenkins 2.540 and...
Unknown
0
Affected Vendor
Jenkins Project
View all reports →Affected Software
Jenkins Fortify Plugin
Vulnerable Versions:
0
Timeline
Official Publish:
August 21st, 2023
Last Modified:
October 1st, 2024
Added to House:
July 22nd, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:N