CVE-2023-35144: Jenkins Maven Repository Server

Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.

Jenkins Maven Repository Server Plugin 1.10 and earlier does not escape project and build display names on the Build Artifacts As Maven Repository page, resulting in a stored cross-site scripting (XSS) vulnerability.

Affected products

  • Jenkins Maven Repository Server: up to and including 1.10

Published 2023-06-14. Last modified 2026-06-17.