Impact
The vulnerability resides in the Jenkins SonarQube Scanner Plugin version 2.18.3 and earlier, where it fails to restrict permissible URL schemes for dashboard links embedded in SonarQube scanner results. This omission permits the use of the "javascript:" scheme, which enables attackers holding Item/Configure rights to embed malicious scripts that persist across configuration changes, leading to stored cross‑site scripting.
Affected Systems
Jenkins deployments utilizing the SonarQube Scanner Plugin up to and including version 2.18.3 are susceptible. This includes any instance where the plugin is installed and active, regardless of company size or Jenkins distribution.
Risk and Exploitability
The CVSS score of 8.0 signals a high severity assessment, and while EPSS data is not available, the lack of a KEV listing indicates no publicly documented exploits as of the data cutoff. Attackers need Item/Configure permission to introduce malicious dashboard links; once injected, the script executes in the context of any user who opens the affected configuration, eroding confidentiality and integrity of Jenkins dashboards.
OpenCVE Enrichment