Lucene search

K
osvGoogleOSV:GHSA-F4GQ-7HVF-FJM3
HistoryMay 24, 2022 - 5:12 p.m.

Stored XSS vulnerability in Jenkins RapidDeploy Plugin

2022-05-2417:12:40
Google
osv.dev
7
jenkins
rapiddeploy plugin
xss
vulnerability
remote server
stored
escaped

EPSS

0.001

Percentile

22.0%

RapidDeploy Plugin 4.2 and earlier does not escape package names in its displayed table of packages obtained from a remote server. This results in a stored cross-site scripting (XSS) vulnerability exploitable by users able to configure jobs.

RapidDeploy Plugin 4.2.1 escapes package names.

EPSS

0.001

Percentile

22.0%

Related for OSV:GHSA-F4GQ-7HVF-FJM3