Stored Cross-Site Scripting Vulnerability in CloudBees Jenkins Health Advisor Plugin
CVE-2025-47885

8.8HIGH

What is CVE-2025-47885?

The Jenkins Health Advisor by CloudBees Plugin has a vulnerability that fails to properly escape responses from the Jenkins Health Advisor server. This oversight allows an attacker who can manipulate server responses to inject malicious scripts, leading to stored cross-site scripting (XSS) attacks. Such vulnerabilities can compromise the integrity of the Jenkins environment and impact user data security.

Affected Version(s)

Jenkins Health Advisor by CloudBees Plugin 0 <= 374.v194b_d4f0c8c8

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-47885 : Stored Cross-Site Scripting Vulnerability in CloudBees Jenkins Health Advisor Plugin