PT-2026-93778 · Jenkins · Coverage Plugin
CVE-2026-92135
·
Published
2026-09-16
·
Updated
2026-09-17
CVSS v3.1
8.0
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Jenkins Coverage Plugin versions 3.3358.v9487dde48783 and earlier
Description
Insufficient validation of the coverage results ID occurs when a job configuration is submitted via the REST API. An attacker with Item/Configure permissions can provide a
javascript: scheme URL as the identifier, leading to stored cross-site scripting (XSS), where malicious scripts are permanently stored on the server and executed in the browser of other users.Recommendations
Update Jenkins Coverage Plugin to a version later than 3.3358.v9487dde48783.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Coverage Plugin