Impact
Jenkins update‑center2 versions 3.18.3 and earlier fail to escape plugin‑provided values such as names, descriptions, and version metadata on plugin download index pages. This omission allows a stored cross‑site scripting vulnerability that can be exploited by attackers who have the ability to host a plugin. The impact of successfully injecting malicious code into the index pages is the execution of arbitrary scripts within the context of the page, potentially enabling session hijacking, data theft, or defacement when users view the vulnerable pages.
Affected Systems
The affected product is Jenkins Project’s update‑center2 component, specifically versions 3.18.3 and earlier. Users running these or older releases may be at risk if the vulnerable index pages are served to end users.
Risk and Exploitability
The vulnerability carries a CVSS score of 5.4, indicating a moderate risk level. EPSS information is not available, and the issue is not included in the CISA KEV catalog. The exploit requires that an attacker can provide a plugin to the update‑center; hence, the attack vector is likely limited to environments where the update‑center accepts untrusted plugin uploads. If such uploads are permitted, the stored XSS can be activated simply by having a user access the affected index page.
OpenCVE Enrichment