GHSA-w22p-4x9f-486v

Suggest an improvement
Source
https://github.com/advisories/GHSA-w22p-4x9f-486v
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-w22p-4x9f-486v/GHSA-w22p-4x9f-486v.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-w22p-4x9f-486v
Aliases
Published
2026-04-29T15:30:38Z
Modified
2026-08-14T20:00:07Z
Severity
  • 9.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H CVSS Calculator
Summary
Jenkins GitHub Plugin has an XSS vulnerability
Details

In Jenkins GitHub Plugin versions 1.46.0 and earlier, the JavaScript that validates the "GitHub hook trigger for GITScm polling" feature improperly processes the current job URL.

This results in a stored cross-site scripting (XSS) vulnerability exploitable by non-anonymous attackers with Overall/Read permission.

GitHub Plugin 1.46.0.1 no longer processes the current job URL as part of JavaScript implementing validation of the feature "GitHub hook trigger for GITScm polling".

Database specific
{
    "cwe_ids":  [
        "CWE-79"
    ],
    "github_reviewed":  true,
    "github_reviewed_at":  "2026-05-06T22:50:26Z",
    "nvd_published_at":  "2026-04-29T14:16:19Z",
    "severity":  "CRITICAL"
}
References

Affected packages

Maven / com.coravy.hudson.plugins.github:github

Package

Name
com.coravy.hudson.plugins.github:github
View open source insights on deps.dev
Purl
pkg:maven/com.coravy.hudson.plugins.github/github

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
1.46.0.1

Affected versions

0.*
0.1
0.2
0.3
0.4
0.5
0.6
0.7
0.8
0.9
1.*
1.0
1.1
1.2
1.3
1.4
1.5
1.6
1.7
1.8
1.9
1.9.1
1.10
1.11
1.11.1
1.11.2
1.11.3
1.12.0-alpha-1
1.12.0
1.12.1
1.13.0-alpha-1
1.13.0-alpha-2
1.13.0
1.13.1
1.13.2
1.13.3
1.14.0-alpha-1
1.14.0-alpha-2
1.14.0
1.14.1
1.14.2
1.15.0
1.16.0
1.17.0
1.17.1
1.18.0
1.18.1
1.18.2
1.19.0
1.19.1
1.19.2
1.19.3
1.20.0
1.21.0
1.21.1
1.22.0
1.22.1
1.22.2
1.22.3
1.22.4
1.23.0
1.23.1
1.24.0
1.25.0
1.25.1
1.26.0
1.26.1
1.26.2
1.27.0
1.28.0
1.28.1
1.29.0
1.29.1
1.29.2
1.29.3
1.29.4
1.29.5
1.30.0
1.31.0
1.32.0
1.33.0
1.33.1
1.34.0
1.34.1
1.34.1.1
1.34.2
1.34.3
1.34.3.1
1.34.4
1.34.5
1.35.0
1.36.0
1.36.1
1.37.0
1.37.1
1.37.2
1.37.3
1.37.3.1
1.38.0
1.39.0
1.40.0
1.41.0
1.42.0
1.43.0
1.44.0
1.45.0
1.46.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/04/GHSA-w22p-4x9f-486v/GHSA-w22p-4x9f-486v.json"