GHSA-rfrq-3v89-fqg6
GitHub Security Advisory
Reflected XSS in Jenkins Compatibility Action Storage Plugin
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Jenkins Compatibility Action Storage Plugin 1.0 and earlier does not escape the content coming from the MongoDB in the testConnection form validation endpoint, resulting in a reflected cross-site scripting (XSS) vulnerability.
Affected Packages
Maven
org.jenkins-ci.plugins:compatibility-action-storage
Affected versions:
0
(last affected: 1.0)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: August 27, 2025 6:31 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.