GHSA-pqg3-xfx2-fmqp
GitHub Security Advisory
Cross site scripting vulnerability in update-center2
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Jenkins update-center2 3.13 and 3.14 renders the required Jenkins core version on plugin download index pages without sanitization, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a plugin for hosting.
Affected Packages
Maven
org.jenkins-ci:update-center2
Affected versions:
3.13
(fixed in 3.15)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: August 25, 2025 6:33 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.