CVE-2025-30196

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Mar 19, 2025
CWE ID 79

Summary

CVE-2025-30196 is a stored cross-site scripting (XSS) vulnerability affecting the Jenkins AnchorChain Plugin version 1.0. The plugin fails to restrict URL schemes for links generated based on workspace content, leading to the exposure of the `javascript:` scheme. Attackers who can manipulate the input file used in the AnchorChain post-build step can exploit this vulnerability to inject malicious scripts and gain unauthorized access to user sessions or steal sensitive information. This weakness can potentially lead to serious security implications, emphasizing the need for timely patching and secure input validation practices.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share