Описание
Improper Neutralization of Input During Web Page Generation in Jenkins Git Plugin
Jenkins Git Plugin 4.2.0 and earlier does not escape the error message for the repository URL for Microsoft TFS field form validation, resulting in a stored cross-site scripting vulnerability.
Пакеты
Наименование
org.jenkins-ci.plugins:git
maven
Затронутые версииВерсия исправления
<= 4.2.0
4.2.1
Связанные уязвимости
CVSS3: 5.4
redhat
почти 6 лет назад
Jenkins Git Plugin 4.2.0 and earlier does not escape the error message for the repository URL for Microsoft TFS field form validation, resulting in a stored cross-site scripting vulnerability.
CVSS3: 5.4
nvd
почти 6 лет назад
Jenkins Git Plugin 4.2.0 and earlier does not escape the error message for the repository URL for Microsoft TFS field form validation, resulting in a stored cross-site scripting vulnerability.