Lucene search

K
osvGoogleOSV:GHSA-FQ52-6CJF-JW59
HistoryMay 24, 2022 - 5:22 p.m.

Reflected XSS vulnerability in Jenkins VncRecorder Plugin

2022-05-2417:22:19
Google
osv.dev
3

0.001 Low

EPSS

Percentile

36.1%

VncRecorder Plugin 1.25 and earlier does not escape a parameter value in the checkVncServ form validation endpoint output.

This results in a reflected cross-site scripting (XSS) vulnerability.

VncRecorder Plugin 1.35 escapes the parameter value in the output.

0.001 Low

EPSS

Percentile

36.1%

Related for OSV:GHSA-FQ52-6CJF-JW59