Database/Control plane, storage & DevOps
Jenkins Customizable Header Plugin: SVG icon config injection yields stored XSS on every page
Impact
The plugin's appearance configuration can be overwritten through Stapler data binding, letting an attacker set a custom SVG icon containing inline JavaScript. Because the header renders on every Jenkins page, the payload executes in the browser of every user including administrators, making credential and session theft on the build controller straightforward. A Jenkins administrator session is the key to the pipelines that build and publish what runs on the GPU nodes. Affects Customizable Header Plugin 295.v2544b_ca_19b_97 and earlier; only clusters that actually installed this plugin are exposed.
Who can reach it
Authenticated low-privileged Jenkins user who can reach the controller over the network and submit the data-bound configuration. Administrator victims are hit passively when they load any Jenkins page.
What to do
The 2026-09-02 advisory (SECURITY-4104) does not list a fixed release in the record here; if no fixed version is available, uninstall or disable the Customizable Header Plugin and reset its appearance configuration. Either way it is a plugin change plus a controller restart - no GPU node maintenance.
References
Related entries
- KubeEdge (ConfigUpdateJob handler, updateFields): REMOTE CODE EXECUTION ON EDGE NODES via a normal Kubernetes APINCVD-2026-051-kubeedge-configupdatejob-handler · KubeEdge (ConfigUpdateJob handler, updateFields)High
- KubeEdge (NodeUpgradeJob handler, v1alpha2 API): REMOTE CODE EXECUTION ON EDGE NODES through the upgrade path. TheNCVD-2026-052-kubeedge-nodeupgradejob-handler · KubeEdge (NodeUpgradeJob handler, v1alpha2 API)High
- APC Network Management Card 4 (NMC4): An unauthenticated attacker can manipulate URL parameters to walk out of the webCVE-2024-58310 · APC Network Management Card 4 (NMC4)High
- Cisco Nexus Dashboard Fabric Controller (SSH host key validation): NDFC does not validate the SSH host keysCVE-2025-20163 · Cisco Nexus Dashboard Fabric Controller (SSH host key validation)High
- MinIO (S3 API, unsigned-trailer uploads): Signature validation on unsigned-trailer uploads is incomplete, so knowingCVE-2025-31489 · MinIO (S3 API, unsigned-trailer uploads)High
- HPE OneView for VMware vCenter (vertical privilege escalation): A read-only user performs administrative actionsCVE-2025-37101 · HPE OneView for VMware vCenter (vertical privilege escalation)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.