Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does...
High severity
Unreviewed
Published
Sep 2, 2026
to the GitHub Advisory Database
•
Updated Sep 2, 2026
Description
Published by the National Vulnerability Database
Sep 2, 2026
Published to the GitHub Advisory Database
Sep 2, 2026
Last updated
Sep 2, 2026
Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL schemes for the dashboard links it creates based on SonarQube scanner results, allowing the
javascript:scheme, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.References