Jenkins Gatling Plugin 136.vb_9009b_3d33a_e serves Gatling reports in a manner that bypasses the Content-Security-Policy protection introduced in Jenkins 1.641 and 1.625, resulting in a cross-site scripting (XSS) vulnerability exploitable by users able to change report content.
History

Wed, 17 Sep 2025 19:15:00 +0000

Type Values Removed Values Added
First Time appeared Jenkins
Jenkins gatling
CPEs cpe:2.3:a:jenkins:gatling:*:*:*:*:*:jenkins:*:*
Vendors & Products Jenkins
Jenkins gatling

Fri, 06 Jun 2025 16:45:00 +0000

Type Values Removed Values Added
References

Fri, 06 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-79
Metrics cvssV3_1

{'score': 8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 06 Jun 2025 13:45:00 +0000

Type Values Removed Values Added
Description Jenkins Gatling Plugin 136.vb_9009b_3d33a_e serves Gatling reports in a manner that bypasses the Content-Security-Policy protection introduced in Jenkins 1.641 and 1.625, resulting in a cross-site scripting (XSS) vulnerability exploitable by users able to change report content.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: jenkins

Published: 2025-06-06T13:32:08.219Z

Updated: 2025-06-06T16:03:44.179Z

Reserved: 2025-06-06T11:53:22.748Z

Link: CVE-2025-5806

cve-icon Vulnrichment

Updated: 2025-06-06T16:03:44.179Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-06T14:15:23.323

Modified: 2025-09-17T19:12:16.560

Link: CVE-2025-5806

cve-icon Redhat

No data.