Loading HuntDB...

GHSA-3hx4-285w-v6mm

GitHub Security Advisory

Jenkins Project Inheritance Plugin vulnerable to cross site scripting

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Jenkins Project Inheritance Plugin 21.04.03 and earlier does not escape the reason a build is blocked in tooltips, resulting in a cross-site scripting (XSS) vulnerability exploitable by attackers able to control the reason a queue item is blocked.

Affected Packages

Maven hudson.plugins:project-inheritance
Affected versions: 0 (last affected: 21.04.03)

Related CVEs

Key Information

GHSA ID
GHSA-3hx4-285w-v6mm
Published
July 1, 2022 12:01 AM
Last Modified
December 9, 2022 2:27 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
hudson.plugins:project-inheritance
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 24, 2025 6:28 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.