Home

Description

Jenkins Gatling Plugin 136.vb_9009b_3d33a_e serves Gatling reports in a manner that bypasses the Content-Security-Policy protection introduced in Jenkins 1.641 and 1.625, resulting in a cross-site scripting (XSS) vulnerability exploitable by users able to change report content.

PUBLISHED Reserved 2025-06-06 | Published 2025-06-06 | Updated 2025-06-06 | Assigner jenkins

Product status

Default status
unaffected

136.vb_9009b_3d33a_e
affected

References

www.openwall.com/lists/oss-security/2025/06/06/8

www.jenkins.io/security/advisory/2025-06-06/ (Jenkins Security Advisory 2025-06-06) vendor-advisory

cve.org (CVE-2025-5806)

nvd.nist.gov (CVE-2025-5806)

Download JSON

Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.