CVE-2023-4303: Jenkins Fortify
Medium severity, CVSS 6.1. EPSS: 0.5% chance of exploitation in the next 30 days.
Jenkins Fortify Plugin 22.1.38 and earlier does not escape the error message for a form validation method, resulting in an HTML injection vulnerability.
Affected products
- Jenkins Fortify: before 22.2.39 (fixed in 22.2.39)
Published 2023-08-21. Last modified 2026-06-17.