Database/Control plane, storage & DevOps
Jenkins Coverage Plugin: unvalidated coverage results ID allows stored XSS in the controller UI
Impact
The Coverage Plugin up to 3.3358.v9487dde48783 does not validate the coverage results ID submitted with a job configuration through the REST API, letting a user with Item/Configure permission store a javascript: scheme URL as the identifier. The payload runs in the browser of anyone who opens that job's coverage report, administrators included, carrying their Jenkins session. This is a separate plugin and a separate fix from the equivalent Warnings Plugin issue, so patching one does not address the other.
Who can reach it
An authenticated Jenkins user with Item/Configure permission submitting a job configuration through the REST API; another user must view the coverage report for the payload to execute.
What to do
Update the Coverage Plugin past 3.3358.v9487dde48783 through the update center and restart the Jenkins controller - controller-only work, no agent or GPU node impact. In the meantime restrict Item/Configure and review coverage results IDs on jobs that were configured via the API.
References
Related entries
- Jenkins OWASP Dependency-Check Plugin: CWE values from reports are rendered unescaped, giving stored XSSCVE-2026-92136 · Jenkins OWASP Dependency-Check Plugin (report CWE rendering)High
- IBM Spectrum Scale / Storage Scale Container Native Storage Access: Programs running inside a container can overcomeCVE-2022-41739 · IBM Spectrum Scale / Storage Scale Container Native Storage AccessHigh
- Linux octeontx2-af (VF rx-mode affecting PF promiscuous state): A VF setting its receive mode causes the *physicalCVE-2026-72312 · Linux octeontx2-af (VF rx-mode affecting PF promiscuous state)High
- Intel Ethernet diagnostics driver for Windows (iqvw64e.sys / iqvw32.sys), shipped with Intel network adapter toolingCVE-2015-2291 · Intel Ethernet diagnostics driver for Windows (iqvw64e.sys / iqvw32.sys), shipped with Intel network adapter toolingHigh
- IBM Spectrum Scale daemon (GSKit cryptographic library dependency): A local attacker takes control of the SpectrumCVE-2018-1431 · IBM Spectrum Scale daemon (GSKit cryptographic library dependency)High
- Arista CloudVision Portal (Configlet Builder API): A read-only CloudVision user escapes their permissions throughCVE-2019-18181 · Arista CloudVision Portal (Configlet Builder API)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.