CVE-2018-1000426: Jenkins Git Changelog
Medium severity, CVSS 6.1. EPSS: 1% chance of exploitation in the next 30 days.
A cross-site scripting vulnerability exists in Jenkins Git Changelog Plugin 2.6 and earlier in GitChangelogSummaryDecorator/summary.jelly, GitChangelogLeftsideBuildDecorator/badge.jelly, GitLogJiraFilterPostPublisher/config.jelly, GitLogBasicChangelogPostPublisher/config.jelly that allows attackers able to control the Git history parsed by the plugin to have Jenkins render arbitrary HTML on some pages.
Affected products
- Jenkins Git Changelog: up to and including 2.6
Published 2019-01-09. Last modified 2026-06-17.