Medium severity5.4NVD Advisory· Published May 16, 2023· Updated Jun 17, 2026
CVE-2023-32977
CVE-2023-32977
Description
Jenkins Pipeline: Job Plugin does not escape the display name of the build that caused an earlier build to be aborted, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to set build display names immediately.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins.workflow:workflow-jobMaven | < 1295.v395eb | 1295.v395eb |
Affected products
3- cpe:2.3:a:jenkins:pipeline\:_job:*:*:*:*:*:jenkins:*:*Range: <=1292.v27d8cc3e2602
- Range: 1295.v395eb_7400005
Patches
Vulnerability mechanics
References
4News mentions
1- Jenkins Security Advisory 2023-05-16Jenkins Security Advisories · May 16, 2023