GHSA-v27q-87jf-j9cr
GitHub Security Advisory
Jenkins Pipeline Aggregator View Plugin vulnerable to Cross-site Scripting
✓ GitHub Reviewed
HIGH
Has CVE
Advisory Details
Jenkins Pipeline Aggregator View Plugin 1.13 and earlier does not escape a variable representing the current view's URL in inline JavaScript, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by authenticated attackers with Overall/Read permission. Version 1.14 obtains the current URL in a way not susceptible to XSS.
Affected Packages
Maven
com.paul8620.jenkins.plugins:pipeline-aggregator-view
Affected versions:
0
(fixed in 1.14)
Related CVEs
Key Information
7.5
/10
Dataset
Last updated: August 25, 2025 6:33 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.