Loading HuntDB...

GHSA-39r3-h8q6-2phq

GitHub Security Advisory

Reflected Cross site scripting in Jenkins Embeddable Build Status Plugin

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Jenkins Embeddable Build Status Plugin 2.0.3 allows specifying a 'link' query parameter that build status badges will link to, without restricting possible values, resulting in a reflected cross-site scripting (XSS) vulnerability.

Embeddable Build Status Plugin 2.0.4 limits URLs to `http` and `https` protocols and correctly escapes the provided value.

Affected Packages

Maven org.jenkins-ci.plugins:embeddable-build-status
Affected versions: 0 (fixed in 2.0.4)

Related CVEs

Key Information

GHSA ID
GHSA-39r3-h8q6-2phq
Published
June 24, 2022 12:00 AM
Last Modified
December 5, 2022 11:25 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
org.jenkins-ci.plugins:embeddable-build-status
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 25, 2025 6:33 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.