Database/Control plane, storage & DevOps
Jenkins Warnings Plugin: unvalidated analysis results ID allows stored XSS in the controller UI
Impact
The Warnings Plugin up to 13.10258.va17d49a78c3b does not validate the analysis results ID submitted with a job configuration through the REST API, so an attacker with Item/Configure permission can set a javascript: scheme URL as the identifier and have it stored and rendered. Anyone who later views the affected job's results page executes the attacker's script with their Jenkins session, including administrators. On a CI controller that holds cluster credentials, an admin-context script run is a route to job creation or credential use rather than just a browser nuisance.
Who can reach it
An authenticated Jenkins user with Item/Configure permission submitting a job configuration through the REST API; a second user must then view the affected page for the payload to fire.
What to do
Update the Warnings Plugin past 13.10258.va17d49a78c3b through the update center and restart the Jenkins controller. No GPU node or agent work is involved. Until the update is applied, restrict Item/Configure to trusted users and inspect existing analysis results IDs on jobs configured through the API.
References
Related entries
- Jenkins Coverage Plugin: unvalidated coverage results ID allows stored XSS in the controller UICVE-2026-92135 · Jenkins Coverage Plugin (coverage results ID validation)High
- Jenkins OWASP Dependency-Check Plugin: CWE values from reports are rendered unescaped, giving stored XSSCVE-2026-92136 · Jenkins OWASP Dependency-Check Plugin (report CWE rendering)High
- IBM Spectrum Scale / Storage Scale Container Native Storage Access: Programs running inside a container can overcomeCVE-2022-41739 · IBM Spectrum Scale / Storage Scale Container Native Storage AccessHigh
- Linux octeontx2-af (VF rx-mode affecting PF promiscuous state): A VF setting its receive mode causes the *physicalCVE-2026-72312 · Linux octeontx2-af (VF rx-mode affecting PF promiscuous state)High
- Intel Ethernet diagnostics driver for Windows (iqvw64e.sys / iqvw32.sys), shipped with Intel network adapter toolingCVE-2015-2291 · Intel Ethernet diagnostics driver for Windows (iqvw64e.sys / iqvw32.sys), shipped with Intel network adapter toolingHigh
- IBM Spectrum Scale daemon (GSKit cryptographic library dependency): A local attacker takes control of the SpectrumCVE-2018-1431 · IBM Spectrum Scale daemon (GSKit cryptographic library dependency)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.