-
CVSS Score
-| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jvnet.hudson.plugins:monitoring | maven | < 1.53.0 | 1.53.0 |
The GitHub patch explicitly adds parameter validation in HudsonMonitoringFilter.java to check for dangerous characters in request parameters, which indicates the original code lacked this critical sanitization. The vulnerability stems from processing user-controlled input without neutralization, a classic XSS vector. The commit's security context (SECURITY-113) and CWE-79 alignment confirm this was the root cause.