Описание
Jenkins Maven Release Plugin vulnerable to Cross-site Scripting
A stored cross site scripting vulnerability in Jenkins Maven Release Plugin 0.14.0 and earlier allowed attackers to inject arbitrary HTML and JavaScript in the plugin-provided web pages in Jenkins.
Variables on affected views are now escaped.
Пакеты
Наименование
org.jenkins-ci.plugins.m2release:m2release
maven
Затронутые версииВерсия исправления
< 0.15.0
0.15.0
Связанные уязвимости
CVSS3: 5.4
nvd
больше 6 лет назад
A stored cross site scripting vulnerability in Jenkins Maven Release Plugin 0.14.0 and earlier allowed attackers to inject arbitrary HTML and JavaScript in the plugin-provided web pages in Jenkins.