Описание
Jenkins Gatling Plugin Vulnerable to Cross-Site Scripting (XSS)
Jenkins Gatling Plugin 136.vb_9009b_3d33a_e serves Gatling reports in a manner that bypasses the Content-Security-Policy protection introduced in Jenkins 1.641 and 1.625, resulting in a cross-site scripting (XSS) vulnerability exploitable by users able to change report content.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2025-5806
- https://github.com/jenkinsci/gatling-plugin/pull/27
- https://github.com/jenkinsci/gatling-plugin/commit/141bd3a811ab641bf618ec588b615cf87469b222
- https://github.com/jenkinsci/gatling-plugin/releases/tag/136.vb_9009b_3d33a_e
- https://www.jenkins.io/security/advisory/2025-06-06/#SECURITY-3588
- http://www.openwall.com/lists/oss-security/2025/06/06/8
Пакеты
Наименование
org.jenkins-ci.plugins:gatling
maven
Затронутые версииВерсия исправления
= 136.vb
Отсутствует
Связанные уязвимости
CVSS3: 8
nvd
15 дней назад
Jenkins Gatling Plugin 136.vb_9009b_3d33a_e serves Gatling reports in a manner that bypasses the Content-Security-Policy protection introduced in Jenkins 1.641 and 1.625, resulting in a cross-site scripting (XSS) vulnerability exploitable by users able to change report content.