CVE-2018-1000113
Description
Jenkins TestLink Plugin 2.12 and earlier has a stored XSS vulnerability that lets attackers control report names to inject malicious HTML or JavaScript.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Jenkins TestLink Plugin 2.12 and earlier has a stored XSS vulnerability that lets attackers control report names to inject malicious HTML or JavaScript.
Vulnerability
Jenkins TestLink Plugin versions 2.12 and earlier contain a stored cross-site scripting (XSS) vulnerability in TestLinkBuildAction/summary.jelly and other related views. An attacker who can control TestLink report names (e.g., through the TestLink API or by compromising the TestLink server) can inject arbitrary HTML and JavaScript into Jenkins pages that display those names. The issue affects all builds using the plugin with a TestLink connection configured [1][2].
Exploitation
An attacker must have the ability to set or modify TestLink report names on the TestLink server. This can be achieved through write access to TestLink database records or by compromising a TestLink admin account. Once a malicious report name containing JavaScript payloads (e.g., in double quotes or script tags) is stored, any Jenkins user viewing the TestLink build action page will trigger the script in their browser. No special Jenkins permissions are required for the victim beyond viewing the affected build dashboard [1][2].
Impact
Successful exploitation allows the attacker to execute arbitrary JavaScript in the context of a Jenkins user's session. This can lead to session hijacking, credential theft, arbitrary actions performed on behalf of the logged-in user, or exposing sensitive build information. The attack does not require direct access to Jenkins itself, only the ability to influence data from the connected TestLink instance [1][2].
Mitigation
The Jenkins security advisory (2018-02-26) does not mention a specific fixed version for the TestLink Plugin. As of the advisory date, users are advised to upgrade to a patched version if one becomes available. No workaround, such as disabling the affected views, was provided in the references. Users should monitor the plugin update page and apply any future release that resolves the XSS issue [1][2].
AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:testlinkMaven | < 2.13 | 2.13 |
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- github.com/advisories/GHSA-3rrg-p8xc-3457ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2018-1000113ghsaADVISORY
- jenkins.io/security/advisory/2018-02-26/ghsax_refsource_CONFIRMWEB
News mentions
0No linked articles in our index yet.