Jenkins Health Advisor by CloudBees Plugin Vulnerable to Cross-Site Scripting
High severity
GitHub Reviewed
Published
May 14, 2025
to the GitHub Advisory Database
•
Updated May 16, 2025
Package
Affected versions
< 374.376.v3a41aa142efe
Patched versions
374.376.v3a_41a_a_142efe
Description
Published by the National Vulnerability Database
May 14, 2025
Published to the GitHub Advisory Database
May 14, 2025
Reviewed
May 16, 2025
Last updated
May 16, 2025
Jenkins Health Advisor by CloudBees Plugin 374.v194b_d4f0c8c8 and earlier does not escape responses from the Jenkins Health Advisor server, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control Jenkins Health Advisor server responses.
References