Описание
Stored XSS vulnerability in Jenkins Active Choices Plugin
Jenkins Active Choices Plugin 2.5.2 and earlier does not escape reference parameter values.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
Jenkins Active Choices Plugin 2.5.3 escapes reference parameter values.
Пакеты
Наименование
org.biouno:uno-choice
maven
Затронутые версииВерсия исправления
<= 2.5.2
2.5.3
Связанные уязвимости
CVSS3: 4.6
nvd
почти 5 лет назад
Jenkins Active Choices Plugin 2.5.2 and earlier does not escape reference parameter values, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.