Описание
Cross-site Scripting in Jenkins Rich Text Publisher Plugin
Jenkins Rich Text Publisher Plugin 1.4 and earlier does not escape the HTML message set by its post-build step, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs.
Пакеты
Наименование
org.jenkins-ci.plugins:rich-text-publisher-plugin
maven
Затронутые версииВерсия исправления
<= 1.4
Отсутствует
Связанные уязвимости
CVSS3: 5.4
nvd
больше 3 лет назад
Jenkins Rich Text Publisher Plugin 1.4 and earlier does not escape the HTML message set by its post-build step, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure jobs.