AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-1000426

MEDIUM · CVSS 6.1 EPSS 0.99%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2019-01-09 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 6.1. It affects Jenkins.

CVE
CVE-2018-1000426
Severity
MEDIUM
CVSS
6.1
EPSS
0.99%
Jenkins

Original NVD Description

A cross-site scripting vulnerability exists in Jenkins Git Changelog Plugin 2.6 and earlier in GitChangelogSummaryDecorator/summary.jelly, GitChangelogLeftsideBuildDecorator/badge.jelly, GitLogJiraFilterPostPublisher/config.jelly, GitLogBasicChangelogPostPublisher/config.jelly that allows attackers able to control the Git history parsed by the plugin to have Jenkins render arbitrary HTML on some pages.

Related CVEs

Other vulnerabilities affecting the same vendor(s)