Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 02 Sep 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Weaknesses | CWE-79 | |
| Metrics |
cvssV3_1
|
Wed, 02 Sep 2026 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Jenkins SonarQube Scanner Plugin 2.18.3 and earlier does not limit URL schemes for the dashboard links it creates based on SonarQube scanner results, allowing the `javascript:` scheme, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: jenkins
Published:
Updated: 2026-09-02T17:04:35.852Z
Reserved: 2026-09-01T21:55:27.034Z
Link: CVE-2026-84665
Updated: 2026-09-02T17:04:28.788Z
Status : Received
Published: 2026-09-02T16:17:31.147
Modified: 2026-09-02T18:21:32.917
Link: CVE-2026-84665
No data.
OpenCVE Enrichment
No data.
-
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')