cbcvebase.
CVE-2025-47885
published 2025-05-14

CVE-2025-47885: Jenkins Health Advisor by CloudBees Plugin 374.v194b_d4f0c8c8 and earlier does not escape responses from the Jenkins Health Advisor server, resulting in a…

high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
Jenkins Health Advisor by CloudBees Plugin 374.v194b_d4f0c8c8 and earlier does not escape responses from the Jenkins Health Advisor server, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to control Jenkins Health Advisor server responses.

Affected

10 ranges
VendorProductVersion rangeFixed in
jenkinscadence_vmanager_plugin
jenkinsdingtalk_plugin
jenkinsenvironment_injector_plugin
jenkinshealth_advisor_by_cloudbees<= 374.v194b_d4f0c8c8
jenkinshealth_advisor_by_cloudbees_plugin
jenkinsmatrix_authorization_strategy_plugin
jenkinsopenid_connect_provider_plugin
jenkinsrole-based_authorization_strategy_plugin
jenkinswso2_oauth_plugin
jenkins_projectjenkins_health_advisor_by_cloudbees_plugin<= 374.v194b_d4f0c8c8