Loading HuntDB...

GHSA-3qxr-q72q-hmwp

GitHub Security Advisory

Jenkins CI Game Plugin allows Cross-Site Scripting (XSS)

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the CI game plugin.

Affected Packages

Maven org.jenkins-ci.plugins:ci-game
Affected versions: 0 (fixed in 1.19)

Related CVEs

Key Information

GHSA ID
GHSA-3qxr-q72q-hmwp
Published
April 23, 2022 12:40 AM
Last Modified
March 12, 2025 3:55 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
org.jenkins-ci.plugins:ci-game
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 24, 2025 6:28 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.