Medium severity6.1NVD Advisory· Published Apr 5, 2018· Updated Jun 17, 2026
CVE-2018-1000144
CVE-2018-1000144
Description
A cross site scripting vulnerability exists in Jenkins Cucumber Living Documentation Plugin 1.0.12 and older in CukedoctorBaseAction#doDynamic that disables the Content-Security-Policy protection for archived artifacts and workspace files, allowing attackers able to control the content of these files to attack Jenkins users.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
org.jenkins-ci.plugins:cucumber-living-documentationMaven | < 1.1.0 | 1.1.0 |
Affected products
2- cpe:2.3:a:jenkins:cucumber_living_documentation:*:*:*:*:*:jenkins:*:*Range: <=1.0.12
Patches
Vulnerability mechanics
References
3- github.com/advisories/GHSA-q7jx-r75r-hgj2ghsaADVISORY
- jenkins.io/security/advisory/2018-03-26/nvdVendor AdvisoryWEB
- nvd.nist.gov/vuln/detail/CVE-2018-1000144ghsaADVISORY
News mentions
0No linked articles in our index yet.