CVE-2023-27904: Jenkins
Medium severity, CVSS 5.3. EPSS: 0.7% chance of exploitation in the next 30 days.
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier prints an error stack trace on agent-related pages when agent connections are broken, potentially revealing information about Jenkins configuration that is otherwise inaccessible to attackers.
Affected products
- Jenkins Jenkins: before 2.375.4 (fixed in 2.375.4); before 2.394 (fixed in 2.394)
Published 2023-03-10. Last modified 2026-06-17.