Jenkins DotCi Plugin 2.40.00 and earlier does not escape the GitHub user name parameter provided to commit notifications when displaying them in a build cause, resulting in a stored cross-site scripting (XSS) vulnerability.
Loading...
Loading...
Score 8.8 from GitHub Security Advisory (severity: HIGH) published 2022-09-22. NVD baseline CVSS 5.4; sources differ by 3.4.
Jenkins DotCi Plugin 2.40.00 and earlier does not escape the GitHub user name parameter provided to commit notifications when displaying them in a build cause, resulting in a stored cross-site scripting (XSS) vulnerability.
September 21, 2022
May 28, 2025
See which npm, PyPI, Go, and Maven packages are affected by CVE-2022-41239
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.