Loading HuntDB...

GHSA-2jgw-28qh-6mg8

GitHub Security Advisory

Jenkins Quay.io trigger Plugin Cross-site Scripting vulnerability

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Jenkins Quay.io trigger Plugin 0.1 and earlier does not limit URL schemes for repository homepage URLs submitted via Quay.io trigger webhooks. This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to submit crafted Quay.io trigger webhook payloads.

Affected Packages

Maven org.jenkins-ci.plugins:quayio-trigger
Affected versions: 0 (last affected: 0.1)

Related CVEs

Key Information

GHSA ID
GHSA-2jgw-28qh-6mg8
Published
April 12, 2023 6:30 PM
Last Modified
April 21, 2023 4:13 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
org.jenkins-ci.plugins:quayio-trigger
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 25, 2025 6:33 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.