GHSA-2jgw-28qh-6mg8
GitHub Security Advisory
Jenkins Quay.io trigger Plugin Cross-site Scripting vulnerability
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Jenkins Quay.io trigger Plugin 0.1 and earlier does not limit URL schemes for repository homepage URLs submitted via Quay.io trigger webhooks. This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to submit crafted Quay.io trigger webhook payloads.
Affected Packages
Maven
org.jenkins-ci.plugins:quayio-trigger
Affected versions:
0
(last affected: 0.1)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: August 25, 2025 6:33 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.