OSV 1.4.0 · github-reviewed · 修改于 2026-08-15 03:48
发布时间
2026-04-29 23:30
GitHub 审查时间
2026-05-07 06:50
NVD 发布时间
2026-04-29 22:16
源文件
advisories/github-reviewed/2026/04/GHSA-w22p-4x9f-486v/GHSA-w22p-4x9f-486v.json
In Jenkins GitHub Plugin versions 1.46.0 and earlier, the JavaScript that validates the "GitHub hook trigger for GITScm polling" feature improperly processes the current job URL.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by non-anonymous attackers with Overall/Read permission.
GitHub Plugin 1.46.0.1 no longer processes the current job URL as part of JavaScript implementing validation of the feature "GitHub hook trigger for GITScm polling".