CVE-2018-1000413: Jenkins Config File Provider

Medium severity, CVSS 5.4. EPSS: 0.9% chance of exploitation in the next 30 days.

A cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.1 and earlier in configfiles.jelly, providerlist.jelly that allows users with the ability to configure configuration files to insert arbitrary HTML into some pages in Jenkins.

Affected products

  • Jenkins Config File Provider: up to and including 3.1

Published 2019-01-09. Last modified 2026-06-17.