Описание
Stored XSS vulnerability in computer-queue-plugin Plugin
computer-queue-plugin Plugin 1.5 and earlier does not escape the agent name in tooltips.
This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.
computer-queue-plugin Plugin 1.6 escapes the agent name in tooltips.
Пакеты
Наименование
jenkins.ci.plugins.computerqueue:computer-queue-plugin
maven
Затронутые версииВерсия исправления
<= 1.5
1.6
Связанные уязвимости
CVSS3: 5.4
nvd
больше 5 лет назад
Jenkins computer-queue-plugin Plugin 1.5 and earlier does not escape the agent name in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Agent/Configure permission.