Jenkins Pipeline: Job Plugin does not escape the display name of the build that caused an earlier build to be aborted, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to set build display names immediately.
[
{
"defaultStatus": "affected",
"product": "Jenkins Pipeline: Job Plugin",
"vendor": "Jenkins Project",
"versions": [
{
"lessThan": "*",
"status": "unaffected",
"version": "1295.v395eb_7400005",
"versionType": "maven"
},
{
"lessThan": "1289.*",
"status": "unaffected",
"version": "1289.1291.vb_7c188e7e7df",
"versionType": "maven"
},
{
"lessThan": "1207.*",
"status": "unaffected",
"version": "1207.1209.v69351208a_5a_7",
"versionType": "maven"
}
]
}
]