GHSA-x97g-3gp9-cf2p
GitHub Security Advisory
Jenkins allows Cross-Site Scripting (XSS) via Crafted URL
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
Cross-site Scripting (XSS) in Jenkins main before 1.482 and LTS before 1.466.2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL that points to Jenkins.
Affected Packages
Maven
org.jenkins-ci.main:jenkins-core
Affected versions:
0
(fixed in 1.466.2)
Maven
org.jenkins-ci.main:jenkins-core
Affected versions:
1.467
(fixed in 1.482)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 5, 2025 6:26 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.