Stored Cross-Site Scripting Vulnerability in Jenkins Coverage Plugin
CVE-2025-67641
8HIGH
What is CVE-2025-67641?
The Jenkins Coverage Plugin, specifically versions up to 2.3054.ve1ff7b_a_a_123b_, contains a stored cross-site scripting vulnerability. This security flaw occurs due to inadequate validation of the configured coverage results ID while creating coverage results. Attackers with Item/Configure permissions can exploit this vulnerability by using a javascript: scheme URL as an identifier when configuring jobs via the REST API. Such an exploit may allow malicious scripts to be stored and later executed in the context of a user’s session, posing significant security risks.
Affected Version(s)
Jenkins Coverage Plugin 0 <= 2.3054.ve1ff7b_a_a_123b_