GHSA-4wj7-rh5h-5qmr
GitHub Security Advisory
Jenkins Dependency Graph Viewer Plugin contains Cross-site Scripting
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
A stored cross site scripting vulnerability in Jenkins Dependency Graph Viewer Plugin 0.13 and earlier allowed attackers able to configure jobs in Jenkins to inject arbitrary HTML and JavaScript in the plugin-provided web pages in Jenkins.
Affected Packages
Maven
org.jenkins-ci.plugins:depgraph-view
Affected versions:
0
(fixed in 0.14)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: August 27, 2025 6:31 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.