Impact
The Jenkins Warnings Plugin versions up to 13.10258.va_17d49a_78c3b fails to validate the analysis results ID supplied in job configuration requests. An attacker who has Item/Configure permission can submit a job configuration through the REST API that includes a malicious URL with the javascript: scheme as the identifier. This flaw allows the attacker to inject and store XSS payloads in Jenkins, potentially enabling cookie theft or session hijacking. The vulnerability is a classic stored XSS weakness, identified as CWE‑79.
Affected Systems
Any Jenkins instance that is running the Jenkins Warnings Plugin of version 13.10258.va_17d49a_78c3b or earlier, and has the plugin enabled. The exploit requires that an attacker possess Item/Configure permission on the target Jenkins server.
Risk and Exploitability
The CVSS score of 8 categorizes this flaw as high severity, while the EPSS score of less than 1% indicates a low probability of widespread exploitation. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires legitimate Item/Configure rights and access to the REST API that accepts job configuration. Once deployed, the stored XSS can affect all users who view the affected job configuration, potentially leading to credential compromise and further privilege escalation.
OpenCVE Enrichment