CVE-2023-43499: Jenkins Build Failure Analyzer

Medium severity, CVSS 5.4. EPSS: 0.6% chance of exploitation in the next 30 days.

Jenkins Build Failure Analyzer Plugin 2.4.1 and earlier does not escape Failure Cause names in build logs, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create or update Failure Causes.

Affected products

  • Jenkins Build Failure Analyzer: before 2.4.2 (fixed in 2.4.2)

Published 2023-09-20. Last modified 2026-06-17.