CVE-2025-5806

high

Description

Jenkins Gatling Plugin 136.vb_9009b_3d33a_e serves Gatling reports in a manner that bypasses the Content-Security-Policy protection introduced in Jenkins 1.641 and 1.625, resulting in a cross-site scripting (XSS) vulnerability exploitable by users able to change report content.

References

https://www.jenkins.io/security/advisory/2025-06-06/#SECURITY-3588

http://www.openwall.com/lists/oss-security/2025/06/06/8

Details

Source: Mitre, NVD

Published: 2025-06-06

Updated: 2025-06-06

Risk Information

CVSS v2

Base Score: 9

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 8

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.00041