cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2023-40350,https://securityvulnerability.io/vulnerability/CVE-2023-40350,Stored Cross-Site Scripting in Jenkins Docker Swarm Plugin by CloudBees,"The Jenkins Docker Swarm Plugin version 1.11 and earlier contains a stored cross-site scripting vulnerability due to improper escaping of data returned from Docker. This oversight allows malicious actors with the ability to control Docker response values to execute arbitrary JavaScript code in the context of the user’s browser, potentially compromising user accounts and exposing sensitive information through the Docker Swarm Dashboard view. To mitigate the risk, it is crucial for users to upgrade to the latest version of the plugin as recommended in the Jenkins Security Advisory.",Jenkins,Jenkins Docker Swarm Plugin,5.4,MEDIUM,0.0004900000058114529,false,,false,false,false,,,false,false,,2023-08-16T15:15:00.000Z,0