Loading HuntDB...

GHSA-gchq-9r68-6jwv

GitHub Security Advisory

Cross-Site Request Forgery in Jenkins Credentials Plugin

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Jenkins Credentials Plugin prior to 2.3.19, 2.3.15.1, 2.3.14.1, 2.3.13.1, 2.3.7.1, and 2.3.0.1 does not escape user-controlled information on a view it provides, resulting in a reflected cross-site scripting (XSS) vulnerability.

Jenkins Credentials Plugin 2.3.19, 2.3.15.1, 2.3.14.1, 2.3.13.1, 2.3.7.1, and 2.3.0.1 restricts the user-controlled information it provides to a safe subset.

Affected Packages

Maven org.jenkins-ci.plugins:credentials
Affected versions: 2.3.16 (fixed in 2.3.19)
Maven org.jenkins-ci.plugins:credentials
Affected versions: 2.3.15 (fixed in 2.3.15.1)
Maven org.jenkins-ci.plugins:credentials
Affected versions: 2.3.14 (fixed in 2.3.14.1)
Maven org.jenkins-ci.plugins:credentials
Affected versions: 2.3.8 (fixed in 2.3.13.1)
Maven org.jenkins-ci.plugins:credentials
Affected versions: 2.3.1 (fixed in 2.3.7.1)
Maven org.jenkins-ci.plugins:credentials
Affected versions: 0 (fixed in 2.3.0.1)

Related CVEs

Key Information

GHSA ID
GHSA-gchq-9r68-6jwv
Published
June 16, 2021 5:24 PM
Last Modified
October 27, 2023 2:31 PM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
org.jenkins-ci.plugins:credentials
GitHub Reviewed
✓ Yes

Dataset

Last updated: July 6, 2025 6:30 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.