CVE-2023-32984

MEDIUM

Jenkins TestNG Results Plugin < 730.v4c5283037693 - Stored Cross-Site Scripting via TestNG Report File Parsing

Title source: llm
STIX 2.1

Description

Jenkins TestNG Results Plugin 730.v4c5283037693 and earlier does not escape several values that are parsed from TestNG report files and displayed on the plugin's test information pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a crafted TestNG report file.

References (1)

Core 1
Core References

Scores

CVSS v3 5.4
EPSS 0.1744
EPSS Percentile 95.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (2)
jenkins/testng_results < 730.v4c5283037693
org.jenkins-ci.plugins/testng-plugin 0 - 730.732.v959aMaven
Published May 16, 2023
Tracked Since Feb 18, 2026