GHSA-6xxf-rwv4-mrjm
GitHub Security Advisory
Stored XSS vulnerability in Jenkins Timestamper Plugin
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Timestamper Plugin 1.11.1 and earlier does not escape or sanitize the HTML formatting used to display the timestamps in console output for builds.
This results in a stored cross-site scripting vulnerability that can be exploited by users with Overall/Administer permission.
Timestamper Plugin 1.11.2 sanitizes the HTML formatting for timestamps and only allows basic, safe HTML formatting.
Affected Packages
Maven
org.jenkins-ci.plugins:timestamper
Affected versions:
0
(fixed in 1.11.2)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: August 27, 2025 6:31 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.