CVE-2025-5806: XSS
Jenkins Gatling Plugin 136.vb9009b3d33ae serves Gatling reports in a manner that bypasses the Content-Security-Policy protection introduced in Jenkins 1.641 and 1.625, resulting in a cross-site scripting (XSS) vulnerability exploitable by users able to change report content.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-5806?
CVE-2025-5806 is classified as a high severity cross-site scripting (XSS) vulnerability.
How do I fix CVE-2025-5806?
To fix CVE-2025-5806, you should update the Jenkins Gatling Plugin to a version that addresses this vulnerability.
Who is affected by CVE-2025-5806?
CVE-2025-5806 affects users of the Jenkins Gatling Plugin and Jenkins versions between 1.625 and 1.641.
What is the nature of the vulnerability in CVE-2025-5806?
CVE-2025-5806 allows attackers to exploit a cross-site scripting vulnerability due to improper handling of Gatling reports.
Can CVE-2025-5806 be exploited remotely?
Yes, CVE-2025-5806 can be exploited remotely by users who can modify report content in Jenkins.