CVE-2023-27904
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/03/2023
Last modified:
28/02/2025
Description
Jenkins 2.393 and earlier, LTS 2.375.3 and earlier prints an error stack trace on agent-related pages when agent connections are broken, potentially revealing information about Jenkins configuration that is otherwise inaccessible to attackers.
Impact
Base Score 3.x
5.30
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:* | 2.375.4 (excluding) | |
| cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:* | 2.394 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



