Loading HuntDB...

GHSA-9m48-54pj-h248

GitHub Security Advisory

Improper Neutralization of Input During Web Page Generation in Jenkins

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

A stored cross-site scripting vulnerability in Jenkins 2.191 and earlier, LTS 2.176.2 and earlier allowed attackers with Overall/Administer permission to configure the update site URL to inject arbitrary HTML and JavaScript in update center web pages.

Affected Packages

Maven org.jenkins-ci.main:jenkins-core
Affected versions: 0 (fixed in 2.176.3)
Maven org.jenkins-ci.main:jenkins-core
Affected versions: 2.177 (fixed in 2.192)

Related CVEs

Key Information

GHSA ID
GHSA-9m48-54pj-h248
Published
May 24, 2022 4:55 PM
Last Modified
June 28, 2022 10:30 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
org.jenkins-ci.main:jenkins-core
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 24, 2025 6:28 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.