GHSA-jmxr-w2jc-qp7w
GitHub Security Advisory
Promotion names in Jenkins promoted builds Plugin are not validated when using Job DSL
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Jenkins promoted builds Plugin provides dedicated support for defining promotions using [Job DSL Plugin](https://plugins.jenkins.io/job-dsl).
promoted builds Plugin 873.v6149db_d64130 and earlier does not validate the names of promotions defined in Job DSL. This allows attackers with Job/Configure permission to create a promotion with an unsafe name. As a result, the promotion name could be used for cross-site scripting (XSS) or to replace other `config.xml` files.
promoted builds Plugin 876.v99d29788b_36b_ and 3.10.1 validates the name of promotions.
Affected Packages
Maven
org.jenkins-ci.plugins:promoted-builds
Affected versions:
0
(fixed in 3.10.1)
Maven
org.jenkins-ci.plugins:promoted-builds
Affected versions:
3.11
(fixed in 876.v99d29788b)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: August 24, 2025 6:28 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.