CVE-2025-5806 - CVE House
Back to Database
Status published Unknown CVE-2025-5806

Jenkins Gatling Plugin 136.vb_9009b_3d33a_e serves Gatling reports in a manner...

Vulnerability Description

Jenkins Gatling Plugin 136.vb_9009b_3d33a_e serves Gatling reports in a manner that bypasses the Content-Security-Policy protection introduced in Jenkins 1.641 and 1.625, resulting in a cross-site scripting (XSS) vulnerability exploitable by users able to change report content.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-5806

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Jenkins Project

View all reports →

Affected Software

Jenkins Gatling Plugin
Vulnerable Versions:
136.vb_9009b_3d33a_e

Timeline

Official Publish: June 6th, 2025
Last Modified: June 6th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)

No CWE data available

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.