Database/Control plane, storage & DevOps
Jenkins SonarQube Scanner Plugin: unrestricted URL scheme in dashboard links causes stored XSS
Impact
Dashboard links built from SonarQube scanner results are not restricted to safe URL schemes, so a javascript: URL can be stored and executed when another user follows the link. An attacker with Item/Configure permission - which many build-owning developers hold - can therefore run script in the browser of a reviewer or administrator on the CI controller. That path leads to session theft on the system that produces the images and model artifacts deployed to GPU nodes. Affects SonarQube Scanner Plugin 2.18.3 and earlier; requires the plugin to be installed.
Who can reach it
Authenticated Jenkins user holding Item/Configure permission, over the network. Exploitation requires a victim to click the poisoned dashboard link.
What to do
Update the SonarQube Scanner Plugin past 2.18.3 per the 2026-09-02 advisory (SECURITY-3989). Plugin update plus controller restart; no GPU node maintenance. Review existing job dashboard links for javascript: URLs before declaring it closed.
References
Related entries
- IBM Spectrum Scale / Storage Scale Container Native Storage Access: Programs running inside a container can overcomeCVE-2022-41739 · IBM Spectrum Scale / Storage Scale Container Native Storage AccessHigh
- Linux octeontx2-af (VF rx-mode affecting PF promiscuous state): A VF setting its receive mode causes the *physicalCVE-2026-72312 · Linux octeontx2-af (VF rx-mode affecting PF promiscuous state)High
- Intel Ethernet diagnostics driver for Windows (iqvw64e.sys / iqvw32.sys), shipped with Intel network adapter toolingCVE-2015-2291 · Intel Ethernet diagnostics driver for Windows (iqvw64e.sys / iqvw32.sys), shipped with Intel network adapter toolingHigh
- IBM Spectrum Scale daemon (GSKit cryptographic library dependency): A local attacker takes control of the SpectrumCVE-2018-1431 · IBM Spectrum Scale daemon (GSKit cryptographic library dependency)High
- Arista CloudVision Portal (Configlet Builder API): A read-only CloudVision user escapes their permissions throughCVE-2019-18181 · Arista CloudVision Portal (Configlet Builder API)High
- MUNGE (SUSE/openSUSE packaging): The munge package's install scripts follow symlinks, so a local attacker who controlsCVE-2019-3691 · MUNGE (SUSE/openSUSE packaging)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.