Описание
Stored Cross-site Scripting vulnerability in Jenkins Team Views Plugin
Jenkins Team Views Plugin 0.9.0 and earlier does not escape team names, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Overall/Read permission.
Пакеты
Наименование
com.sonymobile.jenkins.plugins.teamviews:team-views
maven
Затронутые версииВерсия исправления
<= 0.9.0
Отсутствует
Связанные уязвимости
CVSS3: 5.4
nvd
почти 4 года назад
Jenkins Team Views Plugin 0.9.0 and earlier does not escape team names, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Overall/Read permission.