GHSA-chr6-386q-4m3v
GitHub Security Advisory
Stored Cross-site Scripting vulnerability in Jenkins Folder-based Authorization Strategy Plugin
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Jenkins Folder-based Authorization Strategy Plugin 1.3 and earlier does not escape the names of roles shown on the configuration form, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Overall/Administer permission.
Affected Packages
Maven
io.jenkins.plugins:folder-auth
Affected versions:
0
(fixed in 1.4)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: August 25, 2025 6:33 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.