Loading HuntDB...

GHSA-rfrq-3v89-fqg6

GitHub Security Advisory

Reflected XSS in Jenkins Compatibility Action Storage Plugin

✓ GitHub Reviewed MODERATE Has CVE

Advisory Details

Jenkins Compatibility Action Storage Plugin 1.0 and earlier does not escape the content coming from the MongoDB in the testConnection form validation endpoint, resulting in a reflected cross-site scripting (XSS) vulnerability.

Affected Packages

Maven org.jenkins-ci.plugins:compatibility-action-storage
Affected versions: 0 (last affected: 1.0)

Related CVEs

Key Information

GHSA ID
GHSA-rfrq-3v89-fqg6
Published
May 24, 2022 5:22 PM
Last Modified
December 29, 2022 1:27 AM
CVSS Score
5.0 /10
Primary Ecosystem
Maven
Primary Package
org.jenkins-ci.plugins:compatibility-action-storage
GitHub Reviewed
✓ Yes

Dataset

Last updated: August 27, 2025 6:31 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.