Vulnerability GHSA-j7q2-c6r4-x2jw

High Risk
HIGH RISK
CVSS Score: 8.0
Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
4 years ago
May 24, 2022 at 05:27 PM UTC
Stored XSS vulnerability in Jenkins Git Parameter Plugin
0.4.0 - 0.5.1 and 0.8.0 - 0.8.1
0.4.0 - 0.5.1 and 0.8.0 - 0.8.1

Summary

Stored XSS vulnerability in Jenkins Git Parameter Plugin

Details

Jenkins Git Parameter Plugin 0.9.12 and earlier does not escape the repository field on the 'Build with Parameters' page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

Git Parameter Plugin 0.9.13 escapes the repository field on the 'Build with Parameters' page.

Timeline

Published
4 years ago
May 24, 2022 at 05:27 PM UTC
Last Modified
2 years ago
February 16, 2024 at 08:21 AM UTC