Impact
Jenkins Coverage Plugin fails to validate the coverage results ID when job configuration is submitted via the REST API. An attacker who has Item/Configure permission can supply a URL that uses the javascript: scheme as an identifier; once stored, the malicious script executes in the browser of anyone who later views the job configuration, enabling arbitrary script execution in the user's context.
Affected Systems
The vulnerability exists in Jenkins Coverage Plugin versions 3.3358.v9487dde48783 and lower, which is part of the Jenkins build automation platform.
Risk and Exploitability
The CVSS score of 8 indicates a high‑severity flaw. The EPSS score is below 1%, suggesting a low current exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the attacker to have Item/Configure permission and to use the REST API to submit a job configuration; the stored XSS then affects all users who later view that configuration.
OpenCVE Enrichment