Vulnerability GHSA-fgxc-mxvw-55mv

Medium Risk
MEDIUM RISK
CVSS Score: 5.4
Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
4 years ago
May 24, 2022 at 05:08 PM UTC
Jenkins Git Parameter Plugin vulnerable to stored cross-site scripting (XSS)
0.4.0 - 0.5.1 and 0.8.0 - 0.8.1
0.4.0 - 0.5.1 and 0.8.0 - 0.8.1

Summary

Jenkins Git Parameter Plugin vulnerable to stored cross-site scripting (XSS)

Details

Jenkins Git Parameter Plugin 0.9.11 and earlier does not escape the default value shown on the UI, resulting in a stored cross-site scripting vulnerability exploitable by users with Job/Configure permission.

Timeline

Published
4 years ago
May 24, 2022 at 05:08 PM UTC
Last Modified
2 years ago
February 16, 2024 at 07:56 AM UTC