CVE-2025-27531 – Apache InLong Vulnerability
June 8, 2025Rhadamanthys Stealer – Active IOCs
June 8, 2025CVE-2025-27531 – Apache InLong Vulnerability
June 8, 2025Rhadamanthys Stealer – Active IOCs
June 8, 2025Severity
Medium
Analysis Summary
CVE-2025-5806
Jenkins Gatling Plugin serves Gatling reports in a manner that bypasses the Content-Security-Policy protection introduced in Jenkins, resulting in a cross-site scripting (XSS) vulnerability exploitable by users able to change report content.
Impact
- Cross-Site Scripting
Indicators of Compromise
CVE
CVE-2025-5806
Affected Vendors
- Jenkins
Affected Products
- Jenkins Gatling Plugin - 136.vb_9009b_3d33a_e
Remediation
Upgrade to the latest version of the Jenkins Plugin, available from the Jenkins Security Advisory.