GHSA-f9gf-2q87-5m44
GitHub Security Advisory
Stored XSS vulnerability in Jenkins Scriptler Plugin
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Jenkins Scriptler Plugin 3.3 and earlier does not escape the name of scripts on the UI when asking to confirm their deletion.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to create Scriptler scripts.
Jenkins Scriptler Plugin 3.4 escapes the name of scripts on the UI when asking to confirm their deletion.
Affected Packages
Maven
org.jenkins-ci.plugins:scriptler
Affected versions:
0
(fixed in 3.4)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 5, 2025 6:26 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.