GHSA-x68x-wvm2-hqc8
GitHub Security Advisory
Stored XSS vulnerability in Jenkins Compact Columns Plugin
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Compact Columns Plugin 1.11 and earlier displays the unprocessed job description in tooltips.
This results in a stored cross-site scripting vulnerability that can be exploited by users with Job/Configure permission.
Compact Columns Plugin 1.12 applies the configured markup formatter to the job description shown in tooltips.
Affected Packages
Maven
org.jenkins-ci.plugins:compact-columns
Affected versions:
0
(fixed in 1.12)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: August 27, 2025 6:31 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.