Описание
Stored XSS vulnerability in Jenkins Yet Another Build Visualizer Plugin
Yet Another Build Visualizer Plugin 1.11 and earlier does not escape tooltip content.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by users with Run/Update permission.
Yet Another Build Visualizer Plugin 1.12 escapes tooltip content.
Пакеты
Наименование
com.axis.system.jenkins.plugins.downstream:yet-another-build-visualizer
maven
Затронутые версииВерсия исправления
< 1.12
1.12
Связанные уязвимости
CVSS3: 5.4
nvd
больше 5 лет назад
Jenkins Yet Another Build Visualizer Plugin 1.11 and earlier does not escape tooltip content, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by users with Run/Update permission.