Loading HuntDB...

GHSA-9pvw-8q92-hm9w

GitHub Security Advisory

Stored XSS vulnerability in Jenkins Maven Repository Server Plugin

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Jenkins Maven Repository Server Plugin 1.10 and earlier does not escape the versions of build artifacts on the Build Artifacts As Maven Repository page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control maven project versions in `pom.xml`.

Affected Packages

Maven jenkins:repository
Affected versions: 0 (last affected: 1.10)

Related CVEs

Key Information

GHSA ID
GHSA-9pvw-8q92-hm9w
Published
June 14, 2023 3:30 PM
Last Modified
January 30, 2024 11:12 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
jenkins:repository
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 24, 2025 6:28 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.