GHSA-93qh-vwrm-c5pw

Suggest an improvement
Source
https://github.com/advisories/GHSA-93qh-vwrm-c5pw
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-93qh-vwrm-c5pw/GHSA-93qh-vwrm-c5pw.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-93qh-vwrm-c5pw
Aliases
Downstream
CGA (20)
MINI (7)
Published
2026-06-10T15:31:31Z
Modified
2026-09-10T03:50:49Z
Severity
  • 8.0 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H CVSS Calculator
Summary
Jenkins: Stored XSS vulnerability in node offline cause description
Details

Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not escape the user-provided description of a generic offline cause that could be set through the POST config.xml API, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-06-12T22:15:36Z",
    "nvd_published_at":  "2026-06-10T14:16:37Z",
    "severity":  "HIGH"
}
References

Affected packages

Maven / org.jenkins-ci.main:jenkins-core

Package

Name
org.jenkins-ci.main:jenkins-core
View open source insights on deps.dev
Purl
pkg:maven/org.jenkins-ci.main/jenkins-core

Affected ranges

Type
ECOSYSTEM
Events
Introduced
2.483
Fixed
2.568

Affected versions

2.*
2.483
2.484
2.485
2.486
2.487
2.488
2.489
2.490
2.491
2.492
2.492.1
2.492.2
2.492.3
2.493
2.494
2.495
2.496
2.497
2.498
2.499
2.500
2.501
2.502
2.503
2.504
2.504.1
2.504.2
2.504.3
2.505
2.506
2.507
2.508
2.509
2.510
2.511
2.512
2.513
2.514
2.515
2.516
2.516.1
2.516.2
2.516.3
2.517
2.518
2.519
2.520
2.521
2.522
2.523
2.524
2.525
2.526
2.527
2.528
2.528.1
2.528.2
2.528.3
2.529
2.530
2.531
2.532
2.533
2.534
2.535
2.536
2.537
2.538
2.539
2.540
2.541
2.541.1
2.541.2
2.541.3
2.542
2.543
2.544
2.545
2.546
2.547
2.548
2.549
2.550
2.551
2.552
2.553
2.554
2.555
2.555.1
2.555.2
2.555.3
2.556
2.557
2.558
2.559
2.560
2.561
2.562
2.563
2.564
2.565
2.566
2.567

Database specific

last_known_affected_version_range
"<= 2.567"
source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-93qh-vwrm-c5pw/GHSA-93qh-vwrm-c5pw.json"