Описание
Jenkins Shortcut Job Plugin stored cross-site scripting vulnerability
Jenkins Shortcut Job Plugin 0.4 and earlier does not escape the shortcut redirection URL.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure shortcut jobs.
Shortcut Job Plugin 0.5 escapes the shortcut redirection URL.
Пакеты
Наименование
io.jenkins.plugins:shortcut-job
maven
Затронутые версииВерсия исправления
< 0.5
0.5
Связанные уязвимости
CVSS3: 5.4
nvd
больше 2 лет назад
Jenkins Shortcut Job Plugin 0.4 and earlier does not escape the shortcut redirection URL, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to configure shortcut jobs.