Loading HuntDB...

GHSA-35h9-h439-vvmr

GitHub Security Advisory

Stored Cross-site Scripting vulnerability in Jenkins Environment Dashboard Plugin

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Jenkins Environment Dashboard Plugin 1.1.10 and earlier does not escape the Environment order and the Component order configuration values in its views, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with View/Configure permission.

Affected Packages

Maven io.jenkins.plugins:environment-dashboard
Affected versions: 0 (last affected: 1.1.10)

Related CVEs

Key Information

GHSA ID
GHSA-35h9-h439-vvmr
Published
March 16, 2022 12:00 AM
Last Modified
November 30, 2022 7:39 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
io.jenkins.plugins:environment-dashboard
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 27, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.