GHSA-q87g-7mp5-765q
GitHub Security Advisory
Improper Neutralization of Input During Web Page Generation in Jenkins Script Security Plugin
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Jenkins Script Security Plugin 1.72 and earlier does not correctly escape pending or approved classpath entries on the In-process Script Approval page, resulting in a stored cross-site scripting vulnerability.
Affected Packages
Maven
org.jenkins-ci.plugins:script-security
Affected versions:
0
(fixed in 1.73)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: August 24, 2025 6:28 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.