Lucene search

K
osvGoogleOSV:GHSA-FVWH-WV43-8QJ5
HistoryMay 24, 2022 - 5:28 p.m.

Stored XSS vulnerability in Validating String Parameter Plugin

2022-05-2417:28:25
Google
osv.dev
9

0.001 Low

EPSS

Percentile

22.0%

Validating String Parameter Plugin 2.4 and earlier does not escape regular expressions in tooltips. Additionally, Validating String Parameter Plugin 2.4 does not escape parameter names and parameter descriptions.

This results in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.

Validating String Parameter Plugin 2.5 escapes regular expressions in tooltips and parameter names. Parameter descriptions are rendered using the configured markup formatter.

0.001 Low

EPSS

Percentile

22.0%

Related for OSV:GHSA-FVWH-WV43-8QJ5