-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| org.jenkins-ci.plugins:jobConfigHistory | maven | <= 1227.v7a | 1229.v3039470161a_d |
The vulnerability stems from unsanitized timestamp rendering in history views. Analysis focuses on: 1) The data source (HistoryEntry.getTimestamp) providing raw values, and 2) The view controller (HistoryViewAction.doIndex) responsible for rendering. The advisory explicitly mentions missing sanitization during rendering, implicating these core components. Confidence is high for getTimestamp as data origin, medium for doIndex as the rendering entry point without seeing actual template code.
Ongoing coverage of React2Shell