GPU VulnDB

Database/Control plane, storage & DevOps

Jenkins Warnings Plugin: unvalidated analysis results ID allows stored XSS in the controller UI

CVSS 8.0CVE-2026-92134Control plane, storage & DevOpscurated

Impact

The Warnings Plugin up to 13.10258.va17d49a78c3b does not validate the analysis results ID submitted with a job configuration through the REST API, so an attacker with Item/Configure permission can set a javascript: scheme URL as the identifier and have it stored and rendered. Anyone who later views the affected job's results page executes the attacker's script with their Jenkins session, including administrators. On a CI controller that holds cluster credentials, an admin-context script run is a route to job creation or credential use rather than just a browser nuisance.

Who can reach it

An authenticated Jenkins user with Item/Configure permission submitting a job configuration through the REST API; a second user must then view the affected page for the payload to fire.

What to do

Update the Warnings Plugin past 13.10258.va17d49a78c3b through the update center and restart the Jenkins controller. No GPU node or agent work is involved. Until the update is applied, restrict Item/Configure to trusted users and inspect existing analysis results IDs on jobs configured through the API.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.