Skip to content

[GHSA-93qh-vwrm-c5pw] Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1...#8006

Merged
advisory-database[bot] merged 1 commit into
lohitkolluri/advisory-improvement-8006from
lohitkolluri-GHSA-93qh-vwrm-c5pw
Jun 12, 2026
Merged

[GHSA-93qh-vwrm-c5pw] Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1...#8006
advisory-database[bot] merged 1 commit into
lohitkolluri/advisory-improvement-8006from
lohitkolluri-GHSA-93qh-vwrm-c5pw

Conversation

@lohitkolluri

Copy link
Copy Markdown

Updates

  • Affected products
  • CVSS v3
  • CWEs
  • Description
  • Severity
  • Source code location
  • Summary

Comments
Changes based on the official Jenkins Security Advisory 2026-06-10 (SECURITY-3731) at https://www.jenkins.io/security/advisory/2026-06-10/#SECURITY-3731. CVSS v3.1 vector and score from the advisory's own CVSS calculator link. CWE-79 assigned because this is a stored cross-site scripting vulnerability where user input is not sanitized before rendering as HTML. Maven package org.jenkins-ci.main:jenkins-core identified from the Jenkins project's Maven Central artifacts. Source code at https://github.com/jenkinsci/jenkins.

Copilot stopped work on behalf of lohitkolluri due to an error June 11, 2026 12:18
@github-actions github-actions Bot changed the base branch from main to lohitkolluri/advisory-improvement-8006 June 11, 2026 12:19
@advisory-database advisory-database Bot merged commit aa9fec7 into lohitkolluri/advisory-improvement-8006 Jun 12, 2026
4 checks passed
@advisory-database

Copy link
Copy Markdown
Contributor

Hi @lohitkolluri! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@advisory-database advisory-database Bot deleted the lohitkolluri-GHSA-93qh-vwrm-c5pw branch June 12, 2026 22:15
@daniel-beck

Copy link
Copy Markdown

@lohitkolluri Please don't declare LTS releases to be affected when they're not.

@lohitkolluri

Copy link
Copy Markdown
Author

Hey @daniel-beck

Thanks for pointing that out. This was actually my first contribution to the Advisory Database. I gathered the information from multiple sources discussing the vulnerability, and some of them indicated that those LTS releases were affected, so I included them in the advisory.

I assumed the information had already been validated by the upstream sources I was referencing and didn't realize the affected-version mapping for the Jenkins LTS line was incorrect. I'll make sure to verify version ranges more carefully against the project's own guidance going forward.

Sorry for the confusion, and thanks for the correction.

@daniel-beck

Copy link
Copy Markdown

For future reference, the Jenkins security advisory and the CVE metadata (https://www.cve.org/CVERecord?id=CVE-2026-53441) are the only authoritative sources, and both exclude 2.555.3 from the affected versions.

I gathered the information from multiple sources discussing the vulnerability

Could you provide references to claims that LTS 2.555.3 is affected?

@lohitkolluri

Copy link
Copy Markdown
Author

Thanks for the clarification.

I should still have the references I used somewhere in my browser history or notes. I'll take another look and share them if I can find the exact sources that led me to that conclusion.

I understand now that the Jenkins security advisory and the CVE metadata are the authoritative sources for affected versions, and I'll use those directly for future contributions.

Thanks again for taking the time to point this out. I'll keep it in mind going forward.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants