AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-35141

HIGH · CVSS 8 EPSS 0.86%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-06-14 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2023-35141
Severity
HIGH
CVSS
8
EPSS
0.86%
Jenkins

Original NVD Description

In Jenkins 2.399 and earlier, LTS 2.387.3 and earlier, POST requests are sent in order to load the list of context actions. If part of the URL includes insufficiently escaped user-provided values, a victim may be tricked into sending a POST request to an unexpected endpoint by opening a context menu.