Impact
The Jenkins Gitee Plugin version 1301.v8957053c7902 and earlier fails to escape the sender name supplied in Gitee push webhook payloads. The unescaped value is stored in build causes and rendered by the Jenkins UI without sanitization, giving an attacker the ability to embed arbitrary HTML or JavaScript that will execute in the browser of any user who views the affected build details. This stored XSS flaw allows code injection on the Jenkins web interface.
Affected Systems
The flaw affects Jenkins instances that have the Jenkins Gitee Plugin installed, specifically versions up to and including 1301.v8957053c7902. Any Jenkins job configured to trigger builds via the Gitee webhook endpoint can be vulnerable if the webhook payload is not trusted.
Risk and Exploitability
The vulnerability has a CVSS score of 6.8, indicating medium severity. The EPSS score is less than 1%, suggesting a low current exploitation probability. It is not listed in the CISA KEV catalog. Exploitation requires an attacker to influence the push events on a Gitee repository linked to a vulnerable Jenkins job, which can be achieved by controlling or compromising the repository owner. While the risk is moderate, the impact of successful exploitation can be substantial because injected scripts run with the privileges of the browser user viewing the job.
OpenCVE Enrichment