GHSA-hvcr-927w-qcvq
GitHub Security Advisory
Stored XSS vulnerability in Jenkins Contrast Continuous Application Security Plugin
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Contrast Continuous Application Security Plugin 3.9 and earlier does not escape data returned from the Contrast service when generating a report.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control or modify Contrast service API responses.
Contrast Continuous Application Security Plugin 3.10 escapes the affected data.
Affected Packages
Maven
org.jenkins-ci.plugins:contrast-continuous-application-security
Affected versions:
0
(fixed in 3.10)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: August 27, 2025 6:31 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.