GHSA-8294-mv9c-7m5h
GitHub Security Advisory
Stored XSS vulnerability in Jenkins Maven Metadata Plugin for Jenkins CI server plugin
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Maven Metadata Plugin for Jenkins CI server Plugin 2.2 and earlier does not perform URL validation for the Repository Base URL of List maven artifact versions parameters. This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
Affected Packages
Maven
eu.markov.jenkins.plugin.mvnmeta:maven-metadata-plugin
Affected versions:
0
(last affected: 2.2)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: August 27, 2025 6:31 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.