GHSA-hvmc-7g2x-r3p9
GitHub Security Advisory
Jenkins Cross-Site Scripting vulnerability in help icons
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the tooltip content of help icons. Tooltip values can be contributed by plugins, some of which use user-specified values.
This results in a stored cross-site scripting (XSS) vulnerability.
Jenkins 2.252, LTS 2.235.4 escapes the tooltip content of help icons.
Affected Packages
Maven
org.jenkins-ci.main:jenkins-core
Affected versions:
0
(fixed in 2.235.4)
Maven
org.jenkins-ci.main:jenkins-core
Affected versions:
2.236
(fixed in 2.252)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: November 24, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.