GHSA-3h9w-3jjf-qw2vMediumCVSS 6.8

Jenkins Gitee Plugin 1301.v8957053c7902 and earlier does not escape the sender name from Gitee...

Published
September 16, 2026
Last Modified
September 16, 2026

🔗 CVE IDs covered (1)

📋 Description

Jenkins Gitee Plugin 1301.v8957053c7902 and earlier does not escape the sender name from Gitee push webhook payloads in build causes, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to trigger builds via the Jenkins Gitee Plugin webhook endpoint.

🔗 References (3)