Logging of Excessive Data Affecting org.jenkins-ci.plugins:htmlpublisher package, versions [,427)


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.34% (56th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JAVA-ORGJENKINSCIPLUGINS-10674340
  • published10 Jul 2025
  • disclosed9 Jul 2025
  • creditKyler Katz

Introduced: 9 Jul 2025

CVE-2025-53651  (opens in a new tab)
CWE-779  (opens in a new tab)

How to fix?

Upgrade org.jenkins-ci.plugins:htmlpublisher to version 427 or higher.

Overview

org.jenkins-ci.plugins:htmlpublisher is a plugin for Jenkins that publishes HTML reports.

Affected versions of this package are vulnerable to Logging of Excessive Data in the publishReports functionality. An attacker can obtain sensitive information about the file system structure by reviewing the absolute paths in the build logs .

CVSS Base Scores

version 4.0
version 3.1