Skip to main content
Vulnerability Database/CVE-2025-67641

CVE-2025-67641: Jenkins Coverage Plugin XSS Vulnerability

CVE-2025-67641 is a stored XSS vulnerability in Jenkins Coverage Plugin that allows attackers with Item/Configure permission to inject malicious JavaScript through the REST API. This article covers technical details, affected versions, security impact, and mitigation strategies.

Published:

CVE-2025-67641 Overview

CVE-2025-67641 is a stored cross-site scripting (XSS) vulnerability in the Jenkins Coverage Plugin version 2.3054.ve1ff7b_a_a_123b_ and earlier. The plugin validates the configured coverage results ID only when a job is submitted through the Jenkins UI. Attackers with Item/Configure permission can bypass this validation by submitting the job configuration through the REST API. They can supply a javascript: scheme URL as the identifier, which is later rendered to other users and executes attacker-controlled script in their browser session.

Critical Impact

Authenticated attackers with job configuration rights can store javascript: payloads that execute against any Jenkins user who views the affected coverage results, enabling session abuse and cross-tenant action in the Jenkins UI.

Affected Products

  • Jenkins Coverage Plugin 2.3054.ve1ff7b_a_a_123b_
  • Jenkins Coverage Plugin earlier releases
  • Jenkins controllers loading the vulnerable Coverage Plugin

Discovery Timeline

  • 2025-12-10 - Jenkins publishes Security Advisory SECURITY-3611
  • 2025-12-10 - CVE-2025-67641 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-67641

Vulnerability Analysis

The Coverage Plugin accepts a user-controlled identifier when storing coverage results for a job. The plugin enforces validation of this identifier only in the UI-side job configuration path. The REST API path that creates coverage results reuses the same identifier field without applying the equivalent validation. An attacker with Item/Configure permission can submit a job configuration through the REST API containing a javascript: scheme URL in the coverage results ID. When another authenticated user later navigates the coverage results view, the stored identifier is emitted into the rendered page and the browser executes the attacker script. This is classified as Improper Neutralization of Input During Web Page Generation [CWE-79]. User interaction is required because a victim must load the coverage view, and the scope change reflects that script executes under the Jenkins web origin shared by other users.

Root Cause

Validation of the coverage results ID is implemented in the configuration submission handler used by the Jenkins UI, not in the model layer that persists coverage results. REST API clients bypass the UI handler and reach the persistence path with unvalidated input, allowing dangerous URL schemes to be stored verbatim.

Attack Vector

Exploitation requires an authenticated Jenkins account holding Item/Configure on a target job. The attacker sends a job configuration payload to the Jenkins REST API containing a crafted coverage results identifier using the javascript: scheme. When a privileged user subsequently views the coverage results, the browser interprets the stored URL and executes attacker JavaScript in the Jenkins origin. See the Jenkins Security Advisory SECURITY-3611 for the vendor description.

No verified public exploit code is available for CVE-2025-67641 at the time of writing. Readers should consult the vendor advisory for authoritative technical detail.

Detection Methods for CVE-2025-67641

Indicators of Compromise

  • Coverage results stored on Jenkins jobs where the identifier field begins with javascript: or other non-http(s) URL schemes.
  • Jenkins access logs showing POST or config.xml submissions to /job/<name>/config.xml or REST API endpoints from accounts not previously associated with job configuration changes.
  • Browser console or Content Security Policy reports from Jenkins users indicating blocked inline script execution originating from coverage result pages.

Detection Strategies

  • Audit all persisted Coverage Plugin result identifiers and flag any value that is not an http:// or https:// URL.
  • Correlate REST API job configuration events with the identity of the submitting user and compare against expected change-management activity.
  • Review Jenkins audit logs for unexpected Item/Configure activity on jobs that integrate with the Coverage Plugin.

Monitoring Recommendations

  • Forward Jenkins controller access and audit logs to a centralized logging platform and alert on job configuration writes via the REST API.
  • Monitor for creation of new Jenkins users or API tokens that are then used to modify job coverage configurations.
  • Track plugin inventory on each Jenkins controller to confirm the Coverage Plugin has been upgraded past the vulnerable version.

How to Mitigate CVE-2025-67641

Immediate Actions Required

  • Upgrade the Jenkins Coverage Plugin to a release later than 2.3054.ve1ff7b_a_a_123b_ as published in the vendor advisory.
  • Review existing jobs for coverage results whose identifier contains a non-HTTP(S) scheme and remove or correct them.
  • Rotate Jenkins API tokens for any account that may have been used to submit crafted configurations.

Patch Information

Jenkins addressed CVE-2025-67641 in the Coverage Plugin release referenced in Jenkins Security Advisory SECURITY-3611. The fix applies the coverage results ID validation to the model layer so that submissions through the REST API are validated identically to UI submissions.

Workarounds

  • Restrict Item/Configure permission to a minimal set of trusted users until the plugin is upgraded.
  • Disable the Coverage Plugin on controllers where upgrading is not immediately possible.
  • Enforce a Content Security Policy on the Jenkins controller that blocks execution of javascript: URLs in rendered pages.
bash
# Example: list installed plugin versions on a Jenkins controller via CLI
java -jar jenkins-cli.jar -s https://jenkins.example.com/ -auth user:token \
  list-plugins | grep -i coverage

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.