Loading HuntDB...

GHSA-6xxf-rwv4-mrjm

GitHub Security Advisory

Stored XSS vulnerability in Jenkins Timestamper Plugin

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Timestamper Plugin 1.11.1 and earlier does not escape or sanitize the HTML formatting used to display the timestamps in console output for builds.

This results in a stored cross-site scripting vulnerability that can be exploited by users with Overall/Administer permission.

Timestamper Plugin 1.11.2 sanitizes the HTML formatting for timestamps and only allows basic, safe HTML formatting.

Affected Packages

Maven org.jenkins-ci.plugins:timestamper
Affected versions: 0 (fixed in 1.11.2)

Related CVEs

Key Information

GHSA ID
GHSA-6xxf-rwv4-mrjm
Published
May 24, 2022 5:10 PM
Last Modified
January 5, 2023 8:18 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
org.jenkins-ci.plugins:timestamper
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 27, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.