Loading HuntDB...

GHSA-f9gf-2q87-5m44

GitHub Security Advisory

Stored XSS vulnerability in Jenkins Scriptler Plugin

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Jenkins Scriptler Plugin 3.3 and earlier does not escape the name of scripts on the UI when asking to confirm their deletion.

This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create Scriptler scripts.

Jenkins Scriptler Plugin 3.4 escapes the name of scripts on the UI when asking to confirm their deletion.

Affected Packages

Maven org.jenkins-ci.plugins:scriptler
Affected versions: 0 (fixed in 3.4)

Related CVEs

Key Information

GHSA ID
GHSA-f9gf-2q87-5m44
Published
May 24, 2022 7:20 PM
Last Modified
October 27, 2023 4:09 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
org.jenkins-ci.plugins:scriptler
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 5, 2025 6:26 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.