Loading HuntDB...

GHSA-6954-h5c8-m29f

GitHub Security Advisory

Jenkins Lucene-Search Plugin vulnerable to reflected (XSS) cross-site scripting

✓ GitHub Reviewed HIGH Has CVE

Advisory Details

Jenkins Lucene-Search Plugin 370.v62a5f618cd3a and earlier does not escape the search query parameter displayed on the search result page.

This results in a reflected cross-site scripting (XSS) vulnerability.

Affected Packages

Maven org.jenkins-ci.plugins:lucene-search
Affected versions: 0 (fixed in 387.v938a)

Related CVEs

Key Information

GHSA ID
GHSA-6954-h5c8-m29f
Published
July 28, 2022 12:00 AM
Last Modified
January 3, 2024 1:30 PM
CVSS Score
7.5 /10
Primary Ecosystem
Maven
Primary Package
org.jenkins-ci.plugins:lucene-search
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 25, 2025 6:33 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.