Lucene search

K
osvGoogleOSV:GHSA-9G4M-FFX6-C29G
HistoryMay 24, 2022 - 5:25 p.m.

Jenkins Cross-site Scripting vulnerability in project naming strategy

2022-05-2417:25:24
Google
osv.dev
11

0.005 Low

EPSS

Percentile

76.6%

Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the project naming strategy description, that is displayed on item creation.\n\nThis results in a stored cross-site scripting (XSS) vulnerability exploitable by users with Overall/Manage permission.\n\nJenkins 2.252, LTS 2.235.4 escapes the project naming strategy description.