GHSA-5qpv-27q3-6484
GitHub Security Advisory
Jenkins Violation Plugin allows Cross-Site Scripting (XSS)
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML in the Violations plugin.
Affected Packages
Maven
org.jenkins-ci.plugins:violations
Affected versions:
0
(fixed in 0.7.11)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: August 24, 2025 6:28 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.