Description

Jenkins Coverage Plugin 2.3054.ve1ff7b_a_a_123b_ and earlier does not validate the configured coverage results ID when creating coverage results, only when submitting the job configuration through the UI, allowing attackers with Item/Configure permission to use a `javascript:` scheme URL as identifier by configuring the job through the REST API, resulting in a stored cross-site scripting (XSS) vulnerability.

INFO

Published Date :

2025-12-10T16:50:39.402Z

Last Modified :

2025-12-10T18:16:02.206Z

Source :

jenkins
AFFECTED PRODUCTS

The following products are affected by CVE-2025-67641 vulnerability.

Vendors Products
Jenkins
  • Coverage
REFERENCES

Here, you will find a curated list of external links that provide in-depth information to CVE-2025-67641.

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact