Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-6732 | Jenkins AnchorChain Plugin Has a Cross-Site Scripting (XSS) Vulnerability |
Github GHSA |
GHSA-xxrg-mg63-qfpj | Jenkins AnchorChain Plugin Has a Cross-Site Scripting (XSS) Vulnerability |
Wed, 08 Oct 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Jenkins
Jenkins anchorchain |
|
| CPEs | cpe:2.3:a:jenkins:anchorchain:1.0:*:*:*:*:jenkins:*:* | |
| Vendors & Products |
Jenkins
Jenkins anchorchain |
Wed, 19 Mar 2025 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Wed, 19 Mar 2025 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins AnchorChain Plugin 1.0 does not limit URL schemes for links it creates based on workspace content, allowing the `javascript:` scheme, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control the input file for the Anchor Chain post-build step. | |
| References |
|
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2025-03-19T18:13:51.417Z
Reserved: 2025-03-18T14:36:31.051Z
Link: CVE-2025-30196
Updated: 2025-03-19T17:48:06.230Z
Status : Analyzed
Published: 2025-03-19T16:15:33.950
Modified: 2025-10-08T20:37:09.463
Link: CVE-2025-30196
No data.
OpenCVE Enrichment
No data.
EUVD
Github GHSA