Cross-site Scripting in Jenkins Job Configuration History Plugin
Moderate severity
GitHub Reviewed
Published
Aug 24, 2022
to the GitHub Advisory Database
•
Updated Jan 4, 2024
Package
Affected versions
<= 1165.v8cc9fd1f4597
Patched versions
1166.vc9f255f45b
Description
Published by the National Vulnerability Database
Aug 23, 2022
Published to the GitHub Advisory Database
Aug 24, 2022
Reviewed
Nov 28, 2022
Last updated
Jan 4, 2024
Jenkins Job Configuration History Plugin 1165.v8cc9fd1f4597 and earlier does not escape the job name on the System Configuration History page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure job names.
References