CVE-2018-1000144: Jenkins Cucumber Living Documentation
Medium severity, CVSS 6.1. EPSS: 0.8% chance of exploitation in the next 30 days.
A cross site scripting vulnerability exists in Jenkins Cucumber Living Documentation Plugin 1.0.12 and older in CukedoctorBaseAction#doDynamic that disables the Content-Security-Policy protection for archived artifacts and workspace files, allowing attackers able to control the content of these files to attack Jenkins users.
Affected products
- Jenkins Cucumber Living Documentation: up to and including 1.0.12
Published 2018-04-05. Last modified 2026-06-17.