CyberRota Analysis
AI-GeneratedThe Jenkins SonarQube Scanner Plugin versions 2.18.3 and earlier are vulnerable due to insufficient restrictions on URL schemes for dashboard links, permitting the use of the `javascript:` scheme. This flaw enables stored cross-site scripting (XSS) attacks, which can be exploited by users with Item/Configure permissions to execute malicious scripts. Organizations using this plugin should prioritize remediation to protect against potential exploitation of this vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL schemes for the dashboard links it creates based on SonarQube scanner results, allowing the `javascript:` scheme, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.