Loading HuntDB...

GHSA-chr6-386q-4m3v

GitHub Security Advisory

Stored Cross-site Scripting vulnerability in Jenkins Folder-based Authorization Strategy Plugin

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Jenkins Folder-based Authorization Strategy Plugin 1.3 and earlier does not escape the names of roles shown on the configuration form, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Overall/Administer permission.

Affected Packages

Maven io.jenkins.plugins:folder-auth
Affected versions: 0 (fixed in 1.4)

Related CVEs

Key Information

GHSA ID
GHSA-chr6-386q-4m3v
Published
March 16, 2022 12:00 AM
Last Modified
November 30, 2022 8:28 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
io.jenkins.plugins:folder-auth
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 25, 2025 6:33 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.