Loading HuntDB...

GHSA-2463-7265-h8r4

GitHub Security Advisory

Jenkins Matrix Reloaded Plugin vulnerable to Stored XSS

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Jenkins Matrix Reloaded Plugin 1.1.3 and earlier does not escape the agent name in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.

Affected Packages

Maven net.praqma:matrix-reloaded
Affected versions: 0 (last affected: 1.1.3)

Related CVEs

Key Information

GHSA ID
GHSA-2463-7265-h8r4
Published
July 1, 2022 12:01 AM
Last Modified
December 9, 2022 2:28 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
net.praqma:matrix-reloaded
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 25, 2025 6:33 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.