Jenkins AnchorChain Plugin Has a Cross-Site Scripting (XSS) Vulnerability
High severity
GitHub Reviewed
Published
Mar 19, 2025
to the GitHub Advisory Database
•
Updated Mar 19, 2025
Description
Published by the National Vulnerability Database
Mar 19, 2025
Published to the GitHub Advisory Database
Mar 19, 2025
Reviewed
Mar 19, 2025
Last updated
Mar 19, 2025
Jenkins AnchorChain Plugin 1.0 does not limit URL schemes for links it creates based on workspace content, allowing the javascript: scheme.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control the input file for the Anchor Chain post-build step.
As of publication of this advisory, there is no fix.
References