CVE-2023-27904

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
10/03/2023
Last modified:
28/02/2025

Description

Jenkins 2.393 and earlier, LTS 2.375.3 and earlier prints an error stack trace on agent-related pages when agent connections are broken, potentially revealing information about Jenkins configuration that is otherwise inaccessible to attackers.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:jenkins:jenkins:*:*:*:*:lts:*:*:* 2.375.4 (excluding)
cpe:2.3:a:jenkins:jenkins:*:*:*:*:-:*:*:* 2.394 (excluding)