In Jenkins 2.340 through 2.355 (both inclusive) the tooltip of the build button in list views supports HTML without escaping the job display name, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission. (CVSS:4.3) (Last Update:2022-11-05)Latest security vulnerabilities (Cross Site Scripting (XSS)) (CVSS score >= 4) Read More

ZERO Days Security
Pwn2Own Vancouver 2023 – The Full Schedule
Welcome to Pwn2Own Vancouver for 2023! This year’s event promises some exciting research as we have 19 entries targeting nine different targets – including two