Metrics
Affected Vendors & Products
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 17 Sep 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Jenkins
Jenkins gatling |
|
CPEs | cpe:2.3:a:jenkins:gatling:*:*:*:*:*:jenkins:*:* | |
Vendors & Products |
Jenkins
Jenkins gatling |
Fri, 06 Jun 2025 16:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Fri, 06 Jun 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Weaknesses | CWE-79 | |
Metrics |
cvssV3_1
|
Fri, 06 Jun 2025 13:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Jenkins Gatling Plugin 136.vb_9009b_3d33a_e serves Gatling reports in a manner that bypasses the Content-Security-Policy protection introduced in Jenkins 1.641 and 1.625, resulting in a cross-site scripting (XSS) vulnerability exploitable by users able to change report content. | |
References |
|

Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-06-06T16:03:44.179Z
Reserved: 2025-06-06T11:53:22.748Z
Link: CVE-2025-5806

Updated: 2025-06-06T16:03:44.179Z

Status : Analyzed
Published: 2025-06-06T14:15:23.323
Modified: 2025-09-17T19:12:16.560
Link: CVE-2025-5806

No data.

No data.